Логотип exploitDog
bind:CVE-2017-15044
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2017-15044

Количество 2

Количество 2

nvd логотип

CVE-2017-15044

больше 8 лет назад

The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. An attacker can also gain privileges by modifying text. The default installation is unsafe because the server listens on the network interface, not the localhost interface.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xrxm-gfhq-gw84

почти 4 года назад

The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. An attacker can also gain privileges by modifying text. The default installation is unsafe because the server listens on the network interface, not the localhost interface.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2017-15044

The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. An attacker can also gain privileges by modifying text. The default installation is unsafe because the server listens on the network interface, not the localhost interface.

CVSS3: 8.8
0%
Низкий
больше 8 лет назад
github логотип
GHSA-xrxm-gfhq-gw84

The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. An attacker can also gain privileges by modifying text. The default installation is unsafe because the server listens on the network interface, not the localhost interface.

CVSS3: 8.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу