Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8x7-f6f7-8j2h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.

SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.

EPSS

Процентиль: 64%
0.00476
Низкий

7.2 High

CVSS3

Дефекты

CWE-20
CWE-611

Связанные уязвимости

CVSS3: 7.2
nvd
почти 6 лет назад

SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; does not sufficiently validate the LDAP data source configuration XML document accepted from an untrusted source, leading to Missing XML Validation.

EPSS

Процентиль: 64%
0.00476
Низкий

7.2 High

CVSS3

Дефекты

CWE-20
CWE-611