Описание
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.
Ссылки
- Broken Link
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Permissions RequiredVendor Advisory
- Broken Link
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Permissions RequiredVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 8.10 (включая) до 12.0.17 (исключая)
cpe:2.3:a:pcvuesolutions:pcvue:*:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01114
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-767
CWE-668
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
A Denial Of Service vulnerability exists in PcVue from version 8.10 onward, due to the ability for a non-authorized user to modify information used to validate messages sent by legitimate web clients.
EPSS
Процентиль: 78%
0.01114
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-767
CWE-668