Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3w5-2c4f-pmfr

Опубликовано: 25 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.

IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.

EPSS

Процентиль: 59%
0.00382
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.3
nvd
почти 4 года назад

IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not properly validating RESTAPI configuration data. An authorized user could import invalid data which could be used for an attack. IBM X-Force ID: 220144.

EPSS

Процентиль: 59%
0.00382
Низкий

Дефекты

CWE-22