SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-2171

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.

HIGH 7.5EPSS 42.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 42.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
42.67% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
apache/jetspeed
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.