7.5
CVE-2018-12469
- EPSS 1.05%
- Veröffentlicht 12.10.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:45:16
- Erkennungen
Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microfocus ≫ Enterprise Developer Version <= 2.3
Microfocus ≫ Enterprise Developer Version 2.3 Update update1
Microfocus ≫ Enterprise Developer Version 2.3 Update update2
Microfocus ≫ Enterprise Developer Version 3.0
Microfocus ≫ Enterprise Developer Version 4.0
Microfocus ≫ Enterprise Developer Version 4.0 Update update1
Microfocus ≫ Enterprise Server Version <= 2.3
Microfocus ≫ Enterprise Server Version 2.3 Update update1
Microfocus ≫ Enterprise Server Version 2.3 Update update2
Microfocus ≫ Enterprise Server Version 3.0
Microfocus ≫ Enterprise Server Version 4.0
Microfocus ≫ Enterprise Server Version 4.0 Update update1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.05% | 0.599 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
https://community.microfocus.com/microfocus/mainframe_solutions/enterprise_server/w/knowledge_base/29624/enterprise-server-security-fix-october-2018