Code Execution Vulnerability in F5 WebSafe Alert Server
CVE-2018-5545
8.8HIGH
Summary
A vulnerability exists in the F5 WebSafe Alert Server versions 1.0.0 through 4.2.6, wherein an authenticated user can execute arbitrary code on the server by sending a specially crafted payload. This defect poses a significant risk as it allows potentially harmful operations to be carried out on the server, compromising its integrity and the security of the data it manages. Organizations utilizing this software should review their implementations and apply the latest security updates to mitigate the risk.
Affected Version(s)
F5 WebSafe Alert Server 1.0.0-4.2.6
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved