Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-5182

Опубликовано: 23 янв. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all versions of OES for linux, it applies to OES2015 SP1 before Maintenance Update 11080, OES2015 before Maintenance Update 11079, OES11 SP3 before Maintenance Update 11078, OES11 SP2 before Maintenance Update 11077).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:novell:open_enterprise_server:2.0:*:*:*:*:linux_kernel:*:*
cpe:2.3:a:novell:open_enterprise_server:2015:*:*:*:*:linux_kernel:*:*
cpe:2.3:o:novell:open_enterprise_server:11.0:*:*:*:*:linux_kernel:*:*

EPSS

Процентиль: 76%
0.00988
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all versions of OES for linux, it applies to OES2015 SP1 before Maintenance Update 11080, OES2015 before Maintenance Update 11079, OES11 SP3 before Maintenance Update 11078, OES11 SP2 before Maintenance Update 11077).

EPSS

Процентиль: 76%
0.00988
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Дефекты

CWE-22