Описание
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.4.0.0 (исключая)
cpe:2.3:a:dell:emc_appsync:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.00139
Низкий
8.3 High
CVSS3
8.8 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-598
CWE-384
Связанные уязвимости
github
около 4 лет назад
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.
EPSS
Процентиль: 34%
0.00139
Низкий
8.3 High
CVSS3
8.8 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-598
CWE-384