6.5

CVE-2014-9000

Exploit
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user.  NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.87% 0.945
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://packetstormsecurity.com/files/128799
Exploit
http://seclists.org/fulldisclosure/2014/Oct/107
Exploit
http://seclists.org/fulldisclosure/2014/Oct/98
Exploit
http://www.mulesoft.org/documentation/display/current/Mule+Enterprise+Management+Console+Security+Update
Vendor Advisory