Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c2f-665c-x845

Опубликовано: 09 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.1

Описание

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.

EPSS

Процентиль: 34%
0.00139
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-200
CWE-327
CWE-384

Связанные уязвимости

CVSS3: 5.1
nvd
почти 2 года назад

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.

CVSS3: 5.5
fstec
около 2 лет назад

Уязвимость кроссплатформенной системы управления доступа IBM i Access Client Solutions, связанная с некорректным управлением сеансом, позволяющая нарушителю перехватить сеанс пользователя и раскрыть защищаемую информацию о хэше NT LAN Manager (NTLM)

EPSS

Процентиль: 34%
0.00139
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-200
CWE-327
CWE-384