ZeroHour

CVE-2019-12131

PoC
CVSS 3.1
9.1 critical
EPSS
1%p66
Published
()
Modified
Description

An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and SDC setups are affected.

Vendors
onap
Products
open network automation platform
Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.