Описание
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.
Ссылки
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
- Broken LinkExploitVendor Advisory
- Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkVendor Advisory
- Broken LinkVendor Advisory
- Broken LinkExploitVendor Advisory
- Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:siemens:db4web:3.4:*:*:*:*:*:*:*
cpe:2.3:a:siemens:db4web:3.6:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.0703
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.
EPSS
Процентиль: 91%
0.0703
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-918