8.8
CVE-2018-1192
- EPSS 0.47%
- Veröffentlicht 01.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the SessionID is logged in audit event logs. An attacker can use the SessionID to impersonate a logged-in user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pivotal Software ≫ Cloud Foundry Uaa Version >= 4.5.0 < 4.5.5
Pivotal Software ≫ Cloud Foundry Uaa Version >= 4.7.0 < 4.7.4
Pivotal Software ≫ Cloud Foundry Uaa Version >= 4.8.0 < 4.8.3
Pivotal Software ≫ Cloud Foundry Uaa-release Version45.7
Pivotal Software ≫ Cloud Foundry Uaa-release Version52.7
Pivotal Software ≫ Cloud Foundry Uaa-release Version53.3
Pivotal Software ≫ Cloud Foundry Cf-release Version < 285
Pivotal Software ≫ Cloud Foundry Cf-deployment Version < 1.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.47% | 0.638 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.