5.3
CVE-2017-17675
- EPSS 0.33%
- Veröffentlicht 19.05.2021 14:15:07
- Zuletzt bearbeitet 21.11.2024 03:18:26
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bmc ≫ Remedy Mid-tier Version9.1 Updatesp3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.33% | 0.525 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.