9.3

CVE-2015-5349

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

Data is provided by the National Vulnerability Database (NVD)
ApacheLdap Studio Version0.6.0
ApacheLdap Studio Version0.7.0
ApacheLdap Studio Version0.8.0
ApacheLdap Studio Version0.8.1
ApacheDirectory Studio Version1.0.0
ApacheDirectory Studio Version1.0.1
ApacheDirectory Studio Version1.1.0
ApacheDirectory Studio Version1.1.0 Updaterc1
ApacheDirectory Studio Version1.1.0 Updaterc2
ApacheDirectory Studio Version1.2.0
ApacheDirectory Studio Version1.2.0 Updaterc1
ApacheDirectory Studio Version1.3.0
ApacheDirectory Studio Version1.3.0 Updaterc1
ApacheDirectory Studio Version1.4.0
ApacheDirectory Studio Version1.5.0
ApacheDirectory Studio Version1.5.1
ApacheDirectory Studio Version1.5.2
ApacheDirectory Studio Version1.5.3
ApacheDirectory Studio Version2.0.0 Updatemilestone1
ApacheDirectory Studio Version2.0.0 Updatemilestone2
ApacheDirectory Studio Version2.0.0 Updatemilestone3
ApacheDirectory Studio Version2.0.0 Updatemilestone4
ApacheDirectory Studio Version2.0.0 Updatemilestone5
ApacheDirectory Studio Version2.0.0 Updatemilestone6
ApacheDirectory Studio Version2.0.0 Updatemilestone7
ApacheDirectory Studio Version2.0.0 Updatemilestone8
ApacheDirectory Studio Version2.0.0 Updatemilestone9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.43% 0.788
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.