Lucene search

K
cve[email protected]CVE-2013-2068
HistorySep 28, 2013 - 7:55 p.m.

CVE-2013-2068

2013-09-2819:55:02
CWE-22
web.nvd.nist.gov
21
cve
red hat
cloudforms
management engine
directory traversal
security vulnerability
nvd

9.4 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.624 Medium

EPSS

Percentile

97.9%

Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a … (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.

Affected configurations

NVD
Node
redhatcloudforms_management_engineMatch5.1

9.4 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:C/A:C

7.1 High

AI Score

Confidence

Low

0.624 Medium

EPSS

Percentile

97.9%