Описание
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit.
Ссылки
- Broken Link
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Permissions RequiredVendor Advisory
- Broken Link
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Permissions RequiredVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 8.10 (включая) до 12.0.17 (исключая)
cpe:2.3:a:pcvuesolutions:pcvue:*:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00547
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
NVD-CWE-noinfo
Связанные уязвимости
github
больше 3 лет назад
An information exposure vulnerability exists in PcVue 12, allowing a non-authorized user to access session data of legitimate users.
EPSS
Процентиль: 67%
0.00547
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
NVD-CWE-noinfo