Lucene search

K
cve[email protected]CVE-2019-6716
HistoryMar 21, 2019 - 4:01 p.m.

CVE-2019-6716

2019-03-2116:01:09
CWE-639
web.nvd.nist.gov
25
cve
2019
6716
insecure direct object reference
idor
logonbox
nervepoint access manager
active directory
denial of service
job modification
wicket core

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

9 High

AI Score

Confidence

High

0.068 Low

EPSS

Percentile

93.9%

An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs), which could allow for the possibility of a Denial of Service attack via a modified jobId parameter in a runJob.html GET request.

Affected configurations

NVD
Node
logonboxnervepoint_access_managerMatch1.2rg10
OR
logonboxnervepoint_access_managerMatch1.2rg3
OR
logonboxnervepoint_access_managerMatch1.2rg4
OR
logonboxnervepoint_access_managerMatch1.2rg5
OR
logonboxnervepoint_access_managerMatch1.2rg6
OR
logonboxnervepoint_access_managerMatch1.2rg7
OR
logonboxnervepoint_access_managerMatch1.2rg8
OR
logonboxnervepoint_access_managerMatch1.2rg9
OR
logonboxnervepoint_access_managerMatch1.3rg
OR
logonboxnervepoint_access_managerMatch1.3rg1
OR
logonboxnervepoint_access_managerMatch1.3rg2
OR
logonboxnervepoint_access_managerMatch1.3rg3
OR
logonboxnervepoint_access_managerMatch1.3rg4
OR
logonboxnervepoint_access_managerMatch1.3rg5
OR
logonboxnervepoint_access_managerMatch1.3rg6
OR
logonboxnervepoint_access_managerMatch1.3rg7
OR
logonboxnervepoint_access_managerMatch1.3rg8
OR
logonboxnervepoint_access_managerMatch1.4rg
OR
logonboxnervepoint_access_managerMatch1.4rg1
OR
logonboxnervepoint_access_managerMatch1.4rg2
OR
logonboxnervepoint_access_managerMatch1.4rg3

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

9 High

AI Score

Confidence

High

0.068 Low

EPSS

Percentile

93.9%

Related for CVE-2019-6716