VulnerabilityModified
CVE-2007-1249
MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.
MEDIUM 6.8EPSS 1.05%
Does this matter?
Lower severity and a low EPSS score (1.05%). Track it; it rarely justifies an emergency change on its own.
Description
MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows remote attackers with write permissions to reorder components.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- contelligent/c1 financial services
- Source
- cve@mitre.org
References
- http://osvdb.org/33497
- http://secunia.com/advisories/24364Vendor Advisory
- http://www.contelligent.com/contell/cms/c1web/contelligent/site/contelligent/changelog.html?fromRelease=9.1.4
- http://www.securityfocus.com/bid/22785
- http://www.vupen.com/english/advisories/2007/0814
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32775
- http://osvdb.org/33497
- http://secunia.com/advisories/24364Vendor Advisory
- http://www.contelligent.com/contell/cms/c1web/contelligent/site/contelligent/changelog.html?fromRelease=9.1.4
- http://www.securityfocus.com/bid/22785
- http://www.vupen.com/english/advisories/2007/0814
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32775
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.