Lucene search

K
cve[email protected]CVE-2018-18593
HistoryDec 31, 2018 - 3:29 p.m.

CVE-2018-18593

2018-12-3115:29:00
CWE-22
web.nvd.nist.gov
19
cve-2018-18593
remote directory traversal
remote disclosure
privileged information
ucmdb
configuration management service
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.6 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.4%

Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities could allow Remote Directory Traversal and Remote Disclosure of Privileged Information

Affected configurations

NVD
Node
hpucmdb_configuration_managerMatch10.22
OR
hpucmdb_configuration_managerMatch10.22cup1
OR
hpucmdb_configuration_managerMatch10.22cup2
OR
hpucmdb_configuration_managerMatch10.22cup3
OR
hpucmdb_configuration_managerMatch10.22cup4
OR
hpucmdb_configuration_managerMatch10.22cup5
OR
hpucmdb_configuration_managerMatch10.22cup6
OR
hpucmdb_configuration_managerMatch10.22cup7
OR
hpucmdb_configuration_managerMatch10.33
OR
hpucmdb_configuration_managerMatch10.33cup1
OR
hpucmdb_configuration_managerMatch10.33cup2
OR
hpucmdb_configuration_managerMatch10.33cup3
OR
hpucmdb_configuration_managerMatch2018.02
OR
hpucmdb_configuration_managerMatch2018.05
OR
hpucmdb_configuration_managerMatch2018.08
OR
hpucmdb_configuration_managerMatch2018.11

CNA Affected

[
  {
    "product": "UCMDB Configuration Management Service",
    "vendor": "Micro Focus",
    "versions": [
      {
        "status": "affected",
        "version": "10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.6 High

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

72.4%

Related for CVE-2018-18593