Cross-Site Request Forgery Vulnerability in Micro Focus Enterprise Developer and Server
CVE-2017-5187

8.8HIGH

What is CVE-2017-5187?

A Cross-Site Request Forgery vulnerability exists in the Directory Server component of Micro Focus Enterprise Developer and Enterprise Server, allowing remote unauthenticated attackers to exploit the system. By sending forged requests, these attackers can access and modify sensitive configuration information and execute OS commands. This vulnerability underscores the importance of implementing robust security measures to protect against unauthorized access and manipulation of crucial system settings.

Affected Version(s)

Micro Focus Enterprise Developer, Micro Focus Enterprise Server 2.3 before 2.3 Update 1, 2.3 Update 1 before Hotfix 8, 2.3 Update 2 before Hotfix 9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.