CVE-2002-0664
The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to read or modify import/export scripts.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.32%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The default Access Control Lists (ACLs) of the administration database for ZMerge 4.x and 5.x provides arbitrary users (including anonymous users) with Manager level access, which allows the users to read or modify import/export scripts.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Affected
- granite software/zmerge
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=103134154721846&w=2
- http://www.iss.net/security_center/static/10057.phpVendor Advisory
- http://www.securityfocus.com/bid/5101
- http://marc.info/?l=bugtraq&m=103134154721846&w=2
- http://www.iss.net/security_center/static/10057.phpVendor Advisory
- http://www.securityfocus.com/bid/5101
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.