CVE-2019-3816
26Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 15%
probabilidad de explotación
15%top 4% de las CVE
explotación observada
noninguna fuente lo reporta
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to openwsman server.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
[UNKNOWN] · openwsmanReferencias
http://bugzilla.suse.com/show_bug.cgi?id=1122623http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00065.htmlhttps://access.redhat.com/errata/RHSA-2019:0638https://access.redhat.com/errata/RHSA-2019:0972https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3816https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2V5HJ355RSKMFQ7GRJAHRZNDVXASF7TA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B2HEZ7D7GF3HDF36JLGYXIK5URR66DS4/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CXQP7UDPRZIZ4LM7FEJCTC2EDUYVOR2J/http://www.securityfocus.com/bid/107368http://www.securityfocus.com/bid/107409