Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-27771

Опубликовано: 12 мая 2022
Источник: nvd
CVSS3: 8.2
CVSS3: 7.6
CVSS2: 6.5
EPSS Низкий

Описание

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hcltech:sametime:11.6:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00304
Низкий

8.2 High

CVSS3

7.6 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22
CWE-434

Связанные уязвимости

CVSS3: 7.6
github
больше 3 лет назад

User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when sending chat messages, receiving notifications and/or transferring files.

EPSS

Процентиль: 53%
0.00304
Низкий

8.2 High

CVSS3

7.6 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-22
CWE-434