Lucene search

K
cve[email protected]CVE-2009-4267
HistoryFeb 19, 2018 - 4:29 p.m.

CVE-2009-4267

2018-02-1916:29:00
CWE-116
web.nvd.nist.gov
20
cve-2009-4267
apache
juddi
security vulnerability
log spoofing
nvd

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

6.1 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.8%

The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter.

Affected configurations

Vulners
NVD
Node
apache_software_foundationjuddiRange3.0.03.0.1
CPENameOperatorVersion
apache:juddiapache juddieq3.0.0

CNA Affected

[
  {
    "product": "jUDDI",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "3.0.0 fixed in 3.0.1"
      }
    ]
  }
]

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

6.1 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.8%

Related for CVE-2009-4267