Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mp8r-jgrr-9j4x

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

EPSS

Процентиль: 48%
0.00248
Низкий

7.5 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 7.5
nvd
почти 7 лет назад

OpenAM (Open Source Edition) 13.0 and later does not properly manage sessions, which allows remote authenticated attackers to change the security questions and reset the login password via unspecified vectors.

EPSS

Процентиль: 48%
0.00248
Низкий

7.5 High

CVSS3

Дефекты

CWE-640