Lucene search

K
cve[email protected]CVE-2007-2760
HistoryMay 18, 2007 - 10:30 p.m.

CVE-2007-2760

2007-05-1822:30:00
web.nvd.nist.gov
19
cve-2007-2760
adempiere
security vulnerability
remote authenticated users
read-write privileges

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.2%

The canUpdate function in model/MRole.java in Adempiere before 3.1.6 does not properly validate user roles, which allows remote authenticated read-only users to gain read-write privileges. NOTE: some of these details are obtained from third party information.

Affected configurations

NVD
Node
adempiereadempiereRange3.1.5
CPENameOperatorVersion
adempiere:adempiereadempierele3.1.5

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.2%

Related for CVE-2007-2760