Описание
The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.
Ссылки
- PatchThird Party AdvisoryUS Government Resource
- PatchThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 8.0.0 (исключая)
cpe:2.3:a:auvesy:versiondog:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00135
Низкий
7.3 High
CVSS3
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-732
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.
EPSS
Процентиль: 34%
0.00135
Низкий
7.3 High
CVSS3
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-732
NVD-CWE-noinfo