Lucene search

K
cvelistRedhatCVELIST:CVE-2016-0709
HistoryApr 11, 2016 - 2:00 p.m.

CVE-2016-0709

2016-04-1114:00:00
redhat
www.cve.org
1

7.4 High

AI Score

Confidence

High

0.217 Low

EPSS

Percentile

96.5%

Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a â€Ļ (dot dot) in a ZIP archive entry, as demonstrated by “â€Ļ/â€Ļ/webapps/x.jsp.”

7.4 High

AI Score

Confidence

High

0.217 Low

EPSS

Percentile

96.5%