← volver
CVE-2017-15715explotación observada

CVE-2017-15715

82Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actepss 85%
de la publicación al arma3027 días
Publicada en NVD26 mar
1ª PoC+3027d
VulnCheck+1429d
probabilidad de explotación
85%top 1% de las CVE
explotación observada
síVulnCheck
1 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
2 productos (9 componentes)
Red Hat Enterprise Linux 6 · Red Hat JBoss Enterprise Web Server 2
no_fix_planned: Will not fix
Corregido
16 productos (544 componentes)
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) · Red Hat JBoss Core Services on RHEL 6 Server · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) · Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) · y otros 11
No afectado
4 productos (17 componentes) — porque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 5 · Red Hat JBoss Web Server 3 · Red Hat Mobile Application Platform 4
In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing portion of the filename.
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.