Lucene search

K
nvd[email protected]NVD:CVE-2014-9300
HistoryDec 07, 2014 - 9:59 p.m.

CVE-2014-9300

2014-12-0721:59:01
CWE-352
web.nvd.nist.gov
3

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

61.3%

Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to hijack the authentication of users for requests that access unauthorized URLs and obtain user credentials via a URL in the url parameter.

Affected configurations

Nvd
Node
alfrescoalfrescoRange5.0.acommunity
VendorProductVersionCPE
alfrescoalfresco*cpe:2.3:a:alfresco:alfresco:*:*:*:*:community:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

61.3%

Related for NVD:CVE-2014-9300