Описание
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:eng:spagobi:5.0:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00533
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-94
Связанные уязвимости
github
больше 3 лет назад
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.
EPSS
Процентиль: 67%
0.00533
Низкий
6.8 Medium
CVSS2
Дефекты
CWE-94