← Back

CVE-2018-12469

nvd nist
Published: Oct 12, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination.

Affected (12)

2 products
Enterprise Developer
Enterprise Server
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Microfocus
Up to 2.3
Version 2.3 update1
Version 2.3 update2
Version 3.0
Version 4.0
Version 4.0 update1
Microfocus
Up to 2.3
Version 2.3 update1
Version 2.3 update2
Version 3.0
Version 4.0
Version 4.0 update1

Timeline

No history available yet.