Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjmg-v3gx-g9v9

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

EPSS

Процентиль: 43%
0.00205
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

Business Objects WebIntelligence 2.7.0 through 2.7.4 only enforces access controls on the client, which allows remote authenticated users to delete arbitrary files on the server via a crafted delete request using the InfoView web client.

EPSS

Процентиль: 43%
0.00205
Низкий