7.7

CVE-2016-0362

IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and trigger network traffic to arbitrary intranet or Internet hosts, via a crafted proxy request to a web service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmTririga Application Platform Version3.3.0.0
IbmTririga Application Platform Version3.3.0.1
IbmTririga Application Platform Version3.3.0.2
IbmTririga Application Platform Version3.3.1.0
IbmTririga Application Platform Version3.3.1.1
IbmTririga Application Platform Version3.3.1.2
IbmTririga Application Platform Version3.3.1.3
IbmTririga Application Platform Version3.3.2.0
IbmTririga Application Platform Version3.3.2.1
IbmTririga Application Platform Version3.3.2.2
IbmTririga Application Platform Version3.3.2.3
IbmTririga Application Platform Version3.3.2.4
IbmTririga Application Platform Version3.3.2.5
IbmTririga Application Platform Version3.4.0.0
IbmTririga Application Platform Version3.4.0.1
IbmTririga Application Platform Version3.4.1.0
IbmTririga Application Platform Version3.4.1.1
IbmTririga Application Platform Version3.4.1.2
IbmTririga Application Platform Version3.4.1.3
IbmTririga Application Platform Version3.4.2.0
IbmTririga Application Platform Version3.4.2.1
IbmTririga Application Platform Version3.4.2.2
IbmTririga Application Platform Version3.4.2.3
IbmTririga Application Platform Version3.5.0.0
IbmTririga Application Platform Version3.5.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.304
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.7 3.1 4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N