Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8cc-954v-xv37

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.

AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.

EPSS

Процентиль: 73%
0.00762
Низкий

Связанные уязвимости

nvd
больше 13 лет назад

AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.

EPSS

Процентиль: 73%
0.00762
Низкий