7.5
CVE-2019-10184
- EPSS 3.48%
- Veröffentlicht 25.07.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:36
- Erkennungen
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss Data Grid Version - SwEdition text-only
Redhat ≫ Jboss Enterprise Application Platform Version - SwEdition text-only
Redhat ≫ Jboss Enterprise Application Platform Version 7.0.0
Redhat ≫ Openshift Application Runtimes Version - SwEdition text-only
Redhat ≫ Openshift Application Runtimes Version 1.0
Redhat ≫ Single Sign-on Version - SwEdition text-only
Redhat ≫ Single Sign-on Version 7.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.2
Redhat ≫ Jboss Enterprise Application Platform Version 7.3
Redhat ≫ Jboss Enterprise Application Platform Version 7.4
Redhat ≫ Jboss Enterprise Application Platform Version 7.2
Redhat ≫ Jboss Enterprise Application Platform Version 7.3
Redhat ≫ Jboss Enterprise Application Platform Version 7.4
Redhat ≫ Jboss Enterprise Application Platform Version 7.2
Redhat ≫ Jboss Enterprise Application Platform Version 7.3
Redhat ≫ Single Sign-on Version 7.3
Redhat ≫ Single Sign-on Version 7.3
Redhat ≫ Single Sign-on Version 7.3
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.48% | 0.876 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| RedHat | 5.3 | 3.9 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://access.redhat.com/errata/RHSA-2020:0727
https://access.redhat.com/errata/RHSA-2019:2998
https://access.redhat.com/errata/RHSA-2019:2935
https://access.redhat.com/errata/RHSA-2019:2936
https://access.redhat.com/errata/RHSA-2019:2937
https://access.redhat.com/errata/RHSA-2019:2938
https://access.redhat.com/errata/RHSA-2019:3044
https://access.redhat.com/errata/RHSA-2019:3045
https://access.redhat.com/errata/RHSA-2019:3046
https://access.redhat.com/errata/RHSA-2019:3050
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10184
https://github.com/undertow-io/undertow/pull/794
https://security.netapp.com/advisory/ntap-20220210-0016/