Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qwr-3g3j-q9gj

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.

EPSS

Процентиль: 41%
0.00194
Низкий

8.8 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.8
nvd
почти 8 лет назад

The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.

EPSS

Процентиль: 41%
0.00194
Низкий

8.8 High

CVSS3

Дефекты

CWE-295