Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1833

Опубликовано: 18 дек. 2018
Источник: nvd
CVSS3: 5.3
CVSS2: 3.5
EPSS Низкий

Описание

IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CLI, could exploit this vulnerability to spoof the request header. IBM X-Force ID: 150507.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:event_streams:2018.3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 34%
0.00137
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

IBM Event Streams 2018.3.0 could allow a remote attacker to submit an API request with a fake Host request header. An attacker, who has already gained authorised access via the CLI, could exploit this vulnerability to spoof the request header. IBM X-Force ID: 150507.

EPSS

Процентиль: 34%
0.00137
Низкий

5.3 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

NVD-CWE-noinfo