Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3vc-j27v-38gp

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.

EPSS

Процентиль: 45%
0.00228
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5
nvd
больше 7 лет назад

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user. IBM X-Force ID: 144958.

EPSS

Процентиль: 45%
0.00228
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-287