6.5
CVE-2018-16172
- EPSS 0.6%
- Veröffentlicht 09.01.2019 23:29:03
- Zuletzt bearbeitet 21.11.2024 03:52:13
- CVE-Watchlists
- Unerledigt
Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cybozu ≫ Remote Service Manager Version >= 3.0.0 <= 3.1.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.6% | 0.44 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:P
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
https://jvn.jp/en/jp/JVN23161885/index.html
https://kb.cybozu.support/article/35260/