9.8

CVE-2017-1000009

Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AkeneoProduct Information Management Version1.4.0 Update- SwEditionenterprise
AkeneoProduct Information Management Version1.4.0 Updatebeta1 SwEditionenterprise
AkeneoProduct Information Management Version1.4.0 Updatebeta2 SwEditionenterprise
AkeneoProduct Information Management Version1.4.0 Updatebeta3 SwEditionenterprise
AkeneoProduct Information Management Version1.4.0 Updaterc1 SwEditionenterprise
AkeneoProduct Information Management Version1.4.1 SwEditionenterprise
AkeneoProduct Information Management Version1.4.2 SwEditionenterprise
AkeneoProduct Information Management Version1.4.3 SwEditionenterprise
AkeneoProduct Information Management Version1.4.4 SwEditionenterprise
AkeneoProduct Information Management Version1.4.5 SwEditionenterprise
AkeneoProduct Information Management Version1.4.6 SwEditionenterprise
AkeneoProduct Information Management Version1.4.7 SwEditionenterprise
AkeneoProduct Information Management Version1.4.8 SwEditionenterprise
AkeneoProduct Information Management Version1.4.9 SwEditionenterprise
AkeneoProduct Information Management Version1.4.10 SwEditionenterprise
AkeneoProduct Information Management Version1.4.11 SwEditionenterprise
AkeneoProduct Information Management Version1.4.12 SwEditionenterprise
AkeneoProduct Information Management Version1.4.13 SwEditionenterprise
AkeneoProduct Information Management Version1.4.14 SwEditionenterprise
AkeneoProduct Information Management Version1.4.15 SwEditionenterprise
AkeneoProduct Information Management Version1.4.16 SwEditionenterprise
AkeneoProduct Information Management Version1.4.17 SwEditionenterprise
AkeneoProduct Information Management Version1.4.18 SwEditionenterprise
AkeneoProduct Information Management Version1.4.19 SwEditionenterprise
AkeneoProduct Information Management Version1.4.20 SwEditionenterprise
AkeneoProduct Information Management Version1.4.21 SwEditionenterprise
AkeneoProduct Information Management Version1.4.22 SwEditionenterprise
AkeneoProduct Information Management Version1.4.23 SwEditionenterprise
AkeneoProduct Information Management Version1.4.24 SwEditionenterprise
AkeneoProduct Information Management Version1.4.25 SwEditionenterprise
AkeneoProduct Information Management Version1.4.26 SwEditionenterprise
AkeneoProduct Information Management Version1.4.27 SwEditionenterprise
AkeneoProduct Information Management Version1.5.0 Update- SwEditionenterprise
AkeneoProduct Information Management Version1.5.0 Updatealpha1 SwEditionenterprise
AkeneoProduct Information Management Version1.5.0 Updatebeta1 SwEditionenterprise
AkeneoProduct Information Management Version1.5.0 Updaterc1 SwEditionenterprise
AkeneoProduct Information Management Version1.5.1 SwEditionenterprise
AkeneoProduct Information Management Version1.5.2 SwEditionenterprise
AkeneoProduct Information Management Version1.5.3 SwEditionenterprise
AkeneoProduct Information Management Version1.5.4 SwEditionenterprise
AkeneoProduct Information Management Version1.5.5 SwEditionenterprise
AkeneoProduct Information Management Version1.5.6 SwEditionenterprise
AkeneoProduct Information Management Version1.5.7 SwEditionenterprise
AkeneoProduct Information Management Version1.5.8 SwEditionenterprise
AkeneoProduct Information Management Version1.5.9 SwEditionenterprise
AkeneoProduct Information Management Version1.5.10 SwEditionenterprise
AkeneoProduct Information Management Version1.5.11 SwEditionenterprise
AkeneoProduct Information Management Version1.5.12 SwEditionenterprise
AkeneoProduct Information Management Version1.5.13 SwEditionenterprise
AkeneoProduct Information Management Version1.5.14 SwEditionenterprise
AkeneoProduct Information Management Version1.6.0 Update- SwEditionenterprise
AkeneoProduct Information Management Version1.6.0 Updatealpha1 SwEditionenterprise
AkeneoProduct Information Management Version1.6.0 Updatealpha2 SwEditionenterprise
AkeneoProduct Information Management Version1.6.0 Updaterc1 SwEditionenterprise
AkeneoProduct Information Management Version1.6.1 SwEditionenterprise
AkeneoProduct Information Management Version1.6.2 SwEditionenterprise
AkeneoProduct Information Management Version1.6.3 SwEditionenterprise
AkeneoProduct Information Management Version1.6.4 SwEditionenterprise
AkeneoProduct Information Management Version1.6.5 SwEditionenterprise
AkeneoProduct Information Management Version1.4.0 Update- SwEditioncommunity
AkeneoProduct Information Management Version1.4.0 Updatebeta1 SwEditioncommunity
AkeneoProduct Information Management Version1.4.0 Updatebeta2 SwEditioncommunity
AkeneoProduct Information Management Version1.4.0 Updatebeta3 SwEditioncommunity
AkeneoProduct Information Management Version1.4.0 Updaterc1 SwEditioncommunity
AkeneoProduct Information Management Version1.4.1 SwEditioncommunity
AkeneoProduct Information Management Version1.4.2 SwEditioncommunity
AkeneoProduct Information Management Version1.4.3 SwEditioncommunity
AkeneoProduct Information Management Version1.4.4 SwEditioncommunity
AkeneoProduct Information Management Version1.4.5 SwEditioncommunity
AkeneoProduct Information Management Version1.4.6 SwEditioncommunity
AkeneoProduct Information Management Version1.4.7 SwEditioncommunity
AkeneoProduct Information Management Version1.4.8 SwEditioncommunity
AkeneoProduct Information Management Version1.4.9 SwEditioncommunity
AkeneoProduct Information Management Version1.4.10 SwEditioncommunity
AkeneoProduct Information Management Version1.4.11 SwEditioncommunity
AkeneoProduct Information Management Version1.4.12 SwEditioncommunity
AkeneoProduct Information Management Version1.4.13 SwEditioncommunity
AkeneoProduct Information Management Version1.4.14 SwEditioncommunity
AkeneoProduct Information Management Version1.4.15 SwEditioncommunity
AkeneoProduct Information Management Version1.4.16 SwEditioncommunity
AkeneoProduct Information Management Version1.4.17 SwEditioncommunity
AkeneoProduct Information Management Version1.4.18 SwEditioncommunity
AkeneoProduct Information Management Version1.4.19 SwEditioncommunity
AkeneoProduct Information Management Version1.4.20 SwEditioncommunity
AkeneoProduct Information Management Version1.4.21 SwEditioncommunity
AkeneoProduct Information Management Version1.4.22 SwEditioncommunity
AkeneoProduct Information Management Version1.4.23 SwEditioncommunity
AkeneoProduct Information Management Version1.4.24 SwEditioncommunity
AkeneoProduct Information Management Version1.4.25 SwEditioncommunity
AkeneoProduct Information Management Version1.4.26 SwEditioncommunity
AkeneoProduct Information Management Version1.4.27 SwEditioncommunity
AkeneoProduct Information Management Version1.5.0 Update- SwEditioncommunity
AkeneoProduct Information Management Version1.5.0 Updatealpha1 SwEditioncommunity
AkeneoProduct Information Management Version1.5.0 Updatebeta1 SwEditioncommunity
AkeneoProduct Information Management Version1.5.0 Updaterc1 SwEditioncommunity
AkeneoProduct Information Management Version1.5.1 SwEditioncommunity
AkeneoProduct Information Management Version1.5.2 SwEditioncommunity
AkeneoProduct Information Management Version1.5.3 SwEditioncommunity
AkeneoProduct Information Management Version1.5.4 SwEditioncommunity
AkeneoProduct Information Management Version1.5.5 SwEditioncommunity
AkeneoProduct Information Management Version1.5.6 SwEditioncommunity
AkeneoProduct Information Management Version1.5.7 SwEditioncommunity
AkeneoProduct Information Management Version1.5.8 SwEditioncommunity
AkeneoProduct Information Management Version1.5.9 SwEditioncommunity
AkeneoProduct Information Management Version1.5.10 SwEditioncommunity
AkeneoProduct Information Management Version1.5.11 SwEditioncommunity
AkeneoProduct Information Management Version1.5.12 SwEditioncommunity
AkeneoProduct Information Management Version1.5.13 SwEditioncommunity
AkeneoProduct Information Management Version1.5.14 SwEditioncommunity
AkeneoProduct Information Management Version1.6.0 Update- SwEditioncommunity
AkeneoProduct Information Management Version1.6.0 Updatealpha1 SwEditioncommunity
AkeneoProduct Information Management Version1.6.0 Updatealpha2 SwEditioncommunity
AkeneoProduct Information Management Version1.6.0 Updaterc1 SwEditioncommunity
AkeneoProduct Information Management Version1.6.1 SwEditioncommunity
AkeneoProduct Information Management Version1.6.2 SwEditioncommunity
AkeneoProduct Information Management Version1.6.3 SwEditioncommunity
AkeneoProduct Information Management Version1.6.4 SwEditioncommunity
AkeneoProduct Information Management Version1.6.5 SwEditioncommunity
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.1% 0.928
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.