7.5
CVE-2017-6910
- EPSS 1.97%
- Veröffentlicht 12.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:30:46
- Erkennungen
The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 before hotfix-4, 4.0.7, 4.0.9 before hotfix-19, 4.4.x before 4.4.2 hotfix-1, 4.5.x before 4.5.3 hotfix-1, and Gateway Community and Enterprise Editions before 5.6.0 allow remote attackers to bypass intended access restrictions and obtain sensitive information via vectors related to HTTP request handling.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kaazing ≫ Kaazing Gateway Version < 4.5.3
Kaazing ≫ Kaazing Gateway Version 4.5.3
Kaazing ≫ Kaazing Gateway Version 4.5.3 Update hotfix1
Kaazing ≫ Kaazing Gateway Update hotfix1 SwEdition jms Version >= 4.4.0 < 4.4.2
Kaazing ≫ Kaazing Gateway SwEdition jms Version >= 4.5.0 < 4.5.3
Kaazing ≫ Kaazing Gateway Version 4.0.5 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.0.6 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.0.6 Update hotfix2 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.0.7 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.4.2 Update hotfix1 SwEdition jms
Kaazing ≫ Kaazing Gateway Version 4.5.3 Update hotfix1 SwEdition jms
Tenefit ≫ Kaazing Websocket Gateway SwEdition community Version < 5.6.0
Tenefit ≫ Kaazing Websocket Gateway SwEdition enterprise Version < 5.6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.97% | 0.778 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://support.kaazing.com/hc/en-us/articles/115004752368