Описание
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.2.62.2 (исключая)Версия до 7.2.62.2 (исключая)Версия до 7.1.35.15 (исключая)Версия до 7.2.54.16 (исключая)Версия от 7.2.55.0 (включая) до 7.2.62.2 (исключая)
Одно из
cpe:2.3:a:progress:connection_manager_for_objectscale:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:ecs_connection_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:moveit_web_application_firewall:7.2.62.1:*:*:*:*:*:*:*
cpe:2.3:a:progress:multi-tenant_hypervisor:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
cpe:2.3:o:progress:loadmaster:*:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.25389
Средний
8.4 High
CVSS3
6.8 Medium
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 8.4
github
7 месяцев назад
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
EPSS
Процентиль: 98%
0.25389
Средний
8.4 High
CVSS3
6.8 Medium
CVSS3
Дефекты
CWE-78