Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-5402

Опубликовано: 31 окт. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 9
EPSS Низкий

Описание

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:cloudforms:4.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms_management_engine:5.6:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03126
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-94
CWE-94

Связанные уязвимости

CVSS3: 8.8
redhat
около 9 лет назад

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

CVSS3: 8.8
github
больше 3 лет назад

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

EPSS

Процентиль: 87%
0.03126
Низкий

8.8 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-94
CWE-94