| Vulnerability Name: | CVE-2018-7679 (CCN-145195) | ||||||||||||
| Assigned: | 2018-06-20 | ||||||||||||
| Published: | 2018-06-20 | ||||||||||||
| Updated: | 2021-04-09 | ||||||||||||
| Summary: | Micro Focus Solutions Business Manager versions prior to 11.4 when ASP.NET is configured with execute permission on the virtual directories and does not validate the contents of user avatar images, could lead to remote code execution. | ||||||||||||
| CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-20 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-7679 Source: CCN Type: SERENA Web site SBM 11.4 Release Notes Source: CONFIRM Type: Release Notes, Vendor Advisory http://help.serena.com/doc_center/sbm/ver11_4/sbm_release_notes.htm Source: XF Type: UNKNOWN microfocus-cve20187679-code-exec(145195) Source: CCN Type: Micro Focus Web site Solutions Business Manager | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||