7.8

CVE-2017-1711

IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmNotes Version8.5.0.0
IbmNotes Version8.5.1.0
IbmNotes Version8.5.2.0
IbmNotes Version8.5.3.0
IbmNotes Version9.0.0.0
IbmNotes Version9.0.1.0
IbmClient Application Access Version1.0.1.0
IbmClient Application Access Version1.0.1.1
IbmClient Application Access Version1.0.1.1 Updateinterim_fix_1
IbmClient Application Access Version1.0.1.2 Updateinterim_fix_1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.409
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.