← Back

CVE-2016-0710

nvd nist
Published: Apr 11, 2016Modified: May 6, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.

Affected (1)

Products: Apache: Jetspeed
1 product
Jetspeed
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.3.0

References (12)

Timeline

No history available yet.