ZeroHour

CVE-2016-2171

CVSS 3.0
7.5 high
EPSS
43%p99
Published
()
Modified
Description

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.

Vendors
apache
Products
jetspeed
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.