Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wrc-9xqr-5ph9

Опубликовано: 22 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

EPSS

Процентиль: 91%
0.06212
Низкий

7.2 High

CVSS3

Дефекты

CWE-74
CWE-88

Связанные уязвимости

CVSS3: 7.2
nvd
больше 3 лет назад

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

EPSS

Процентиль: 91%
0.06212
Низкий

7.2 High

CVSS3

Дефекты

CWE-74
CWE-88