Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-px4v-wj8p-cq36

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

EPSS

Процентиль: 99%
0.84766
Высокий

8.8 High

CVSS3

Дефекты

CWE-22
CWE-434
CWE-78

Связанные уязвимости

CVSS3: 9.9
nvd
больше 4 лет назад

SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with the privilege of the Java Server process. These commands can be used to read or modify any information on the server or shut the server down making it unavailable.

CVSS3: 9.9
fstec
больше 4 лет назад

Уязвимость инструмента моделирования на основе браузера Visual Composer программной интеграционной платформы SAP NetWeaver, позволяющая нарушителю повысить свои привилегии, выполнить произвольные команды или вызвать отказ в обслуживании

EPSS

Процентиль: 99%
0.84766
Высокий

8.8 High

CVSS3

Дефекты

CWE-22
CWE-434
CWE-78