Описание
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the Content Manager server.
Уязвимые конфигурации
Конфигурация 1Версия от 9.1 (включая) до 9.3 (включая)
cpe:2.3:a:microfocus:content_manager:*:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01004
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Manager 9.1, 9.2, and 9.3 when configured to use the ADFS authentication method. The vulnerability could be exploited by an unauthenticated remote attacker to upload content to arbitrary locations on the Content Manager server.
EPSS
Процентиль: 77%
0.01004
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-434