9.4
CVE-2019-6716
- EPSS 3.38%
- Veröffentlicht 21.03.2019 16:01:09
- Zuletzt bearbeitet 21.11.2024 04:47:00
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Logonbox ≫ Nervepoint Access Manager Version1.2 Updaterg10
Logonbox ≫ Nervepoint Access Manager Version1.2 Updaterg3
Logonbox ≫ Nervepoint Access Manager Version1.2 Updaterg4
Logonbox ≫ Nervepoint Access Manager Version1.2 Updaterg5
Logonbox ≫ Nervepoint Access Manager Version1.2 Updaterg6
Logonbox ≫ Nervepoint Access Manager Version1.2 Updaterg7
Logonbox ≫ Nervepoint Access Manager Version1.2 Updaterg8
Logonbox ≫ Nervepoint Access Manager Version1.2 Updaterg9
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg1
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg2
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg3
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg4
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg5
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg6
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg7
Logonbox ≫ Nervepoint Access Manager Version1.3 Updaterg8
Logonbox ≫ Nervepoint Access Manager Version1.4 Updaterg
Logonbox ≫ Nervepoint Access Manager Version1.4 Updaterg1
Logonbox ≫ Nervepoint Access Manager Version1.4 Updaterg2
Logonbox ≫ Nervepoint Access Manager Version1.4 Updaterg3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.38% | 0.871 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.4 | 3.9 | 5.5 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.