Lucene search

K
cve[email protected]CVE-2006-5932
HistoryNov 16, 2006 - 12:07 a.m.

CVE-2006-5932

2006-11-1600:07:00
web.nvd.nist.gov
28
cve
kahua
access control
authentication
nvd
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.025 Low

EPSS

Percentile

90.1%

Kahua before 0.7, when running multiple applications under a single supervisor, grants application access on the basis of username instead of username and database name, which allows remote authenticated users to obtain unauthorized access if different databases assign the same username to different user accounts.

Affected configurations

NVD
Node
kahuakahuaMatch0.1
OR
kahuakahuaMatch0.2
OR
kahuakahuaMatch0.3
OR
kahuakahuaMatch0.4
OR
kahuakahuaMatch0.5
OR
kahuakahuaMatch0.6

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.6 Medium

AI Score

Confidence

Low

0.025 Low

EPSS

Percentile

90.1%

Related for CVE-2006-5932