Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-1552

Опубликовано: 01 нояб. 2017
Источник: nvd
CVSS3: 5.4
CVSS2: 4.9
EPSS Низкий

Описание

IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 131396.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:infosphere_biginsights:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:infosphere_biginsights:4.2.5:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.0019
Низкий

5.4 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
больше 3 лет назад

IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 131396.

EPSS

Процентиль: 41%
0.0019
Низкий

5.4 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-79