Lucene search

K
cveZdiCVE-2017-16607
HistoryJan 23, 2018 - 1:29 a.m.

CVE-2017-16607

2018-01-2301:29:01
CWE-200
zdi
web.nvd.nist.gov
21
cve-2017-16607
netgain enterprise manager
remote attackers
sensitive information disclosure
authentication bypass
heapdumps.jsp
lack of validation
zdi-can-4718
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.012

Percentile

85.5%

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within heapdumps.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download heap memory dump. An attacker can leverage this in conjunction with other vulnerabilities to disclose sensitive information in the context of the current process. Was ZDI-CAN-4718.

Affected configurations

Nvd
Vulners
Node
netgain-systemsenterprise_managerRange<7.2.766
VendorProductVersionCPE
netgain-systemsenterprise_manager*cpe:2.3:a:netgain-systems:enterprise_manager:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "NetGain Systems Enterprise Manager",
    "vendor": "NetGain Systems",
    "versions": [
      {
        "status": "affected",
        "version": "v7.2.586 build 877"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.012

Percentile

85.5%

Related for CVE-2017-16607