5
CVE-2008-3717
- EPSS 1.26%
- Veröffentlicht 19.08.2008 19:41:00
- Zuletzt bearbeitet 16.06.2026 22:56:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids, which allows remote attackers to obtain sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.26% | 0.657 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://secunia.com/advisories/31503
http://sourceforge.net/project/shownotes.php?release_id=619864
http://www.securityfocus.com/bid/30706
http://sourceforge.net/tracker/index.php?func=detail&aid=2040324&group_id=82171&atid=1098812
https://exchange.xforce.ibmcloud.com/vulnerabilities/44485