CVE-2023-29411
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow
changes to administrative credentials, leading to potential remote code execution without
requiring prior authentication on the Java RMI interface.
Affected (2)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.5-ga-01-22320 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.5-gs-01-22320 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 10 | All versions |
Microsoft Windows 11 | All versions |
Microsoft Windows Server 2016 | All versions |
Microsoft Windows Server 2019 | All versions |
Microsoft Windows Server 2022 | All versions |
References (2)
Source: cybersecurity@se.com
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory
Timeline
No history available yet.