8.8
CVE-2017-7429
- EPSS 0.19%
- Published 02.03.2018 20:29:00
- Last modified 21.11.2024 03:31:52
- Source security@opentext.com
- Teams watchlist Login
- Open Login
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
Data is provided by the National Vulnerability Database (NVD)
Microfocus ≫ Edirectory Version <= 8.8.8
Netiq ≫ Edirectory Version8.8.8 Updatepatch10
Netiq ≫ Edirectory Version8.8.8 Updatepatch5
Netiq ≫ Edirectory Version8.8.8 Updatepatch6
Netiq ≫ Edirectory Version8.8.8 Updatepatch7
Netiq ≫ Edirectory Version8.8.8 Updatepatch8
Netiq ≫ Edirectory Version8.8.8 Updatepatch9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.19% | 0.416 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
security@opentext.com | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.