8.8
CVE-2017-7429
- EPSS 0.84%
- Veröffentlicht 02.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:52
- Erkennungen
Fix for NetIQ shell code upload
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Edirectory Version <= 8.8.8
Netiq ≫ Edirectory Version 8.8.8 Update patch10
Netiq ≫ Edirectory Version 8.8.8 Update patch5
Netiq ≫ Edirectory Version 8.8.8 Update patch6
Netiq ≫ Edirectory Version 8.8.8 Update patch7
Netiq ≫ Edirectory Version 8.8.8 Update patch8
Netiq ≫ Edirectory Version 8.8.8 Update patch9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.84% | 0.545 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
| OpenText | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://www.novell.com/support/kb/doc.php?id=3426981
https://bugzilla.suse.com/show_bug.cgi?id=1024957
https://www.netiq.com/documentation/edir88/edir88810hf1_releasenotes/data/edir88810hf1_releasenotes.html