Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5402

Опубликовано: 30 нояб. 2016
Источник: redhat
CVSS3: 8.8
CVSS2: 8.5
EPSS Низкий

Описание

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1357559cfme: RCE via Capacity & Utilization feature

EPSS

Процентиль: 93%
0.05931
Низкий

8.8 High

CVSS3

8.5 High

CVSS2

Связанные уязвимости

CVSS3: 8.8
nvd
почти 8 лет назад

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

CVSS3: 8.8
github
больше 4 лет назад

A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user CFME runs as.

EPSS

Процентиль: 93%
0.05931
Низкий

8.8 High

CVSS3

8.5 High

CVSS2