PT-2017-6294 · Sap · Hybris Commerce

Publicado

2017-08-28

·

Atualizado

2019-08-27

·

CVE-2014-8871

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions hybris Commerce software suite versions 5.0.3.3 and earlier hybris Commerce software suite versions 5.0.0.3 and earlier hybris Commerce software suite versions 5.0.4.4 and earlier hybris Commerce software suite versions 5.1.0.1 and earlier hybris Commerce software suite versions 5.1.1.2 and earlier hybris Commerce software suite versions 5.2.0.3 and earlier hybris Commerce software suite versions 5.3.0.1 and earlier
Description The issue is related to a directory traversal vulnerability.
Recommendations For hybris Commerce software suite versions 5.0.3.3 and earlier, update to a version later than 5.0.3.3. For hybris Commerce software suite versions 5.0.0.3 and earlier, update to a version later than 5.0.0.3. For hybris Commerce software suite versions 5.0.4.4 and earlier, update to a version later than 5.0.4.4. For hybris Commerce software suite versions 5.1.0.1 and earlier, update to a version later than 5.1.0.1. For hybris Commerce software suite versions 5.1.1.2 and earlier, update to a version later than 5.1.1.2. For hybris Commerce software suite versions 5.2.0.3 and earlier, update to a version later than 5.2.0.3. For hybris Commerce software suite versions 5.3.0.1 and earlier, update to a version later than 5.3.0.1.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-8871

Produtos afetados

Hybris Commerce