5.9

CVE-2010-3300

It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Owasp ≫ Enterprise Security Api For Java Version 2.0 Update -
Owasp ≫ Enterprise Security Api For Java Version 2.0 Update rc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.357
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-649 Reliance on Obfuscation or Encryption of Security-Relevant Inputs without Integrity Checking

The product uses obfuscation or encryption of inputs that should not be mutable by an external actor, but the product does not use integrity checks to detect if those inputs have been modified.

https://seclists.org/oss-sec/2010/q3/357
Third Party Advisory
Mailing List
https://www.usenix.org/legacy/events/woot10/tech/full_papers/Rizzo.pdf
Third Party Advisory