7.8
CVE-2019-18245
- EPSS 0.11%
- Veröffentlicht 11.12.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:54
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Reliablecontrols ≫ Rc-licensemanager Version <= 3.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.307 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-428 Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.