VulnerabilityModified
CVE-2016-2171
The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.
HIGH 7.5EPSS 42.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 42.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 42.67% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apache/jetspeed
- Source
- secalert@redhat.com
References
- http://haxx.ml/post/140552592371/remote-code-execution-in-apache-jetspeed-230-and
- http://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3CB9165E38-F3D8-496D-8642-8A53FCAC736A%40gmail.com%3EVendor Advisory
- https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-2171Patch, Vendor Advisory
- http://haxx.ml/post/140552592371/remote-code-execution-in-apache-jetspeed-230-and
- http://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3CB9165E38-F3D8-496D-8642-8A53FCAC736A%40gmail.com%3EVendor Advisory
- https://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-2171Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.