Apache jUDDI 3.0.0 Console Security Issue
CVE-2009-4267

6.5MEDIUM

Key Information:

Vendor
Apache
Status
Vendor
CVE Published:
19 February 2018

Summary

The Apache jUDDI 3.0.0 console contains an input validation flaw that does not properly escape line feeds. This vulnerability permits remote authenticated users to manipulate log entries by leveraging the 'numRows' parameter, potentially leading to misleading log information. Proper handling and escaping of user inputs are essential to prevent such security issues.

Affected Version(s)

jUDDI 3.0.0 fixed in 3.0.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.