Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3702

Опубликовано: 17 мар. 2015
Источник: redhat
CVSS2: 6.4

Описание

Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a .. (dot dot) the session parameter.

Отчет

Red Hat does not currently ship eNovance edeploy in a product form and as such this issue has been filed upstream.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1eDeployAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1153470eDeploy: Path traversal in the session parameter

6.4 Medium

CVSS2

Связанные уязвимости

CVSS3: 9.1
nvd
больше 8 лет назад

Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a .. (dot dot) the session parameter.

CVSS3: 9.1
debian
больше 8 лет назад

Directory traversal vulnerability in eNovance eDeploy allows remote at ...

CVSS3: 9.1
github
больше 3 лет назад

Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a .. (dot dot) the session parameter.

6.4 Medium

CVSS2