ZeroHour

CVE-2019-11642

CVSS 3.0
8.8 high
EPSS
2%p73
Published
()
Modified
Description

A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authenticated remote adversaries can poison log files by entering malicious payloads in either headers or form elements. These payloads are then executed via a client side debugging console. This is predicated on the debugging console and Java Bean being made available to the deployed application.

Vendors
oneshield
Products
oneshield policy
Weakness
CWE-94
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.