Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-0489

Опубликовано: 27 фев. 2018
Источник: nvd
CVSS3: 6.5
CVSS2: 6.4
EPSS Низкий

Описание

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:shibboleth:xmltooling-c:*:*:*:*:*:*:*:*
Версия до 1.6.4 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:arubanetworks:clearpass:*:*:*:*:*:*:*:*
Версия от 6.6.0 (включая) до 6.6.9 (включая)
cpe:2.3:a:arubanetworks:clearpass:*:*:*:*:*:*:*:*
Версия от 6.7.0 (включая) до 6.7.2 (исключая)

EPSS

Процентиль: 47%
0.00243
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.

CVSS3: 8.1
redhat
почти 8 лет назад

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.

CVSS3: 6.5
debian
почти 8 лет назад

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Pr ...

CVSS3: 6.5
github
больше 3 лет назад

Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.

suse-cvrf
почти 8 лет назад

Security update for xmltooling

EPSS

Процентиль: 47%
0.00243
Низкий

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-347