Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5349

Опубликовано: 11 апр. 2016
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

A flaw was found in the CSV export in Apache LDAP Studio and Apache Directory Studio, where it does not properly escape field values. This flaw allows attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of OpenJDK 11javax.injectNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=1987038apache-directory: command injection via crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet

EPSS

Процентиль: 80%
0.01431
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
почти 10 лет назад

The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

CVSS3: 7.8
debian
почти 10 лет назад

The CSV export in Apache LDAP Studio and Apache Directory Studio befor ...

CVSS3: 7.8
github
больше 3 лет назад

Apache Directory Studio Command Injection

EPSS

Процентиль: 80%
0.01431
Низкий

7.8 High

CVSS3