9.1
CVE-2021-40684
- EPSS 0.62%
- Veröffentlicht 22.09.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:24:34
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Talend ≫ Esb Runtime Version >= 5.1 < 7.1.1-r2021-09
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.62% | 0.691 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|