Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vxm-9c9f-7q2m

Опубликовано: 10 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.

EPSS

Процентиль: 37%
0.00159
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.1
nvd
около 1 года назад

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.

CVSS3: 9.1
fstec
больше 1 года назад

Уязвимость компонента Adobe Document Service программного средства создания и развертывания веб-приложений SAP NetWeaver AS for Java, позволяющая нарушителю осуществить SSRF-атаку

EPSS

Процентиль: 37%
0.00159
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-918