5

CVE-2008-2318

The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.

Data is provided by the National Vulnerability Database (NVD)
AppleXCode Version1.5
AppleXCode Version2.2
AppleXcode Tools Version <= 3.0
AppleXcode Tools Version1.0
AppleXcode Tools Version2.0
AppleXcode Tools Version2.1
AppleXcode Tools Version2.2.1
AppleXcode Tools Version2.3
AppleXcode Tools Version2.4
AppleXcode Tools Version2.4.1
AppleXcode Tools Version2.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.48% 0.62
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.