Описание
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute arbitrary code.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:ibm:sterling_external_authentication_server:2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_external_authentication_server:2.3.01:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_external_authentication_server:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_external_authentication_server:2.4.1:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00121
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-78
Связанные уязвимости
github
почти 4 года назад
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute arbitrary code.
EPSS
Процентиль: 31%
0.00121
Низкий
7.8 High
CVSS3
7.2 High
CVSS2
Дефекты
CWE-78