Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-37027

Опубликовано: 21 сент. 2022
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ahsay:cloud_backup_suite:9.1.4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06212
Низкий

7.2 High

CVSS3

Дефекты

CWE-88
CWE-88

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

EPSS

Процентиль: 91%
0.06212
Низкий

7.2 High

CVSS3

Дефекты

CWE-88
CWE-88