ZeroHour

CVE-2017-11467

PoC
CVSS 3.0
9.8 critical
EPSS
73%p99
Published
()
Modified
Description

OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.

Vendors
orientdb
Products
orientdb
Weakness
CWE-269
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news