Insecure HTTP Methods Vulnerability in Apache OpenMeetings Software
CVE-2017-7685
5.3MEDIUM
Summary
The vulnerability in Apache OpenMeetings 1.0.0 arises from the software's inappropriate handling of certain HTTP methods, specifically PUT, DELETE, HEAD, and PATCH. This weakness allows attackers to potentially manipulate resources on the server, leading to unauthorized actions if not adequately secured. Understanding this vulnerability is crucial for safeguarding systems using this software.
Affected Version(s)
Apache OpenMeetings 1.0.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved