PT-2018-9488 · Open Microscopy Environment · Omero.Server
Published
2018-08-20
·
Updated
2018-10-12
·
CVE-2018-1000635
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OMERO.server versions 5.4.0 through 5.4.6
Description
The issue is related to Information Exposure Through Sent Data in OMERO.server, which can allow an attacker to gain full administrative access to the server and potentially disable it.
Recommendations
For OMERO.server versions 5.4.0 through 5.4.6, update to version 5.4.7 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Omero.Server