Lucene search

K
cveApacheCVE-2014-0043
HistoryOct 03, 2017 - 1:29 a.m.

CVE-2014-0043

2017-10-0301:29:00
CWE-200
apache
web.nvd.nist.gov
26
apache
wicket
classpath
vulnerability
security
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

26.9%

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.

Affected configurations

Nvd
Vulners
Node
apachewicketMatch1.5.10
OR
apachewicketMatch6.13.0
VendorProductVersionCPE
apachewicket1.5.10cpe:2.3:a:apache:wicket:1.5.10:*:*:*:*:*:*:*
apachewicket6.13.0cpe:2.3:a:apache:wicket:6.13.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Apache Wicket",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "1.5.10"
      },
      {
        "status": "affected",
        "version": "6.13.0"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

26.9%

Related for CVE-2014-0043