PT-2017-2829 · Orientdb · Orientdb

CVE-2017-11467

·

Publicado

2017-06-19

·

Atualizado

2024-02-14

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OrientDB versions prior to 2.2.22
Description The issue is related to insufficient access control in certain functions, specifically where, fetchplan, and order by. This allows remote attackers to execute arbitrary OS commands via a crafted request. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For OrientDB versions prior to 2.2.22, update to a version that enforces privilege requirements during the use of where, fetchplan, or order by to prevent the execution of arbitrary OS commands. As a temporary workaround, consider restricting access to these functions to minimize the risk of exploitation.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02109
CVE-2017-11467
GHSA-XM6R-4466-MR74

Produtos afetados

Orientdb