Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-0486

Опубликовано: 12 янв. 2018
Источник: redhat
CVSS3: 8.7
EPSS Низкий

Описание

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6xmltoolingNot affected
Red Hat JBoss Data Virtualization 6xmltoolingNot affected
Red Hat JBoss Enterprise Application Platform 6xmltoolingNot affected
Red Hat JBoss Fuse 6xmltoolingNot affected
Red Hat JBoss Fuse Service Works 6xmltoolingNot affected
Red Hat JBoss Operations Network 3XMLToolingNot affected
Red Hat JBoss Portal 6xmltoolingNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1534647xmltooling: impersonation attack and sensitive information disclosure in the Service Provider via crafted DTD

EPSS

Процентиль: 76%
0.00921
Низкий

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 6.5
nvd
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 6.5
debian
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Pr ...

suse-cvrf
около 8 лет назад

Security update for xmltooling

suse-cvrf
около 8 лет назад

Security update for xmltooling

EPSS

Процентиль: 76%
0.00921
Низкий

8.7 High

CVSS3