BDU:2021-04903
Scores
EPSS Score
0.0000
CVSS
3.x 8.1
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
All CVSS Scores
Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Description
Уязвимость веб-сервера Apache HTTP Server связана с недостатками ограничения имени пути к каталогу. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код или прочитать произвольные файлы в целевой системе
Sources
Related Vulnerabilities
Reference Links
Vulnerable Software
Type: Configuration
Vendor: apache software foundation
Product: apache http server
Operating System: fedora 34
{
"version_exact": "2.4.49"
}
Source: bdu
Type: Configuration
Vendor: apache software foundation
Product: apache http server
Operating System: opensuse tumbleweed *
{
"version_exact": "2.4.49"
}
Source: bdu
Type: Configuration
Vendor: apache software foundation
Product: apache http server
Operating System: debian gnu/linux 10
{
"version_exact": "2.4.49"
}
Source: bdu
Type: Configuration
Vendor: apache software foundation
Product: apache http server
Operating System: strelets *
{
"version_exact": "2.4.49"
}
Source: bdu
Type: Configuration
Vendor: apache software foundation
Product: apache http server
Operating System: осон основа оnyx *
{
"version_exact": "2.4.49"
}
Source: bdu
Type: Configuration
Vendor: apache software foundation
Product: apache http server
Operating System: altlinux 8
{
"version_exact": "2.4.49"
}
Source: bdu
Type: Configuration
Vendor: apache software foundation
Product: apache http server
Operating System: fedora 35
{
"version_exact": "2.4.49"
}
Source: bdu
Type: Configuration
Vendor: apache software foundation
Product: apache http server
Operating System: debian gnu/linux 11
{
"version_exact": "2.4.49"
}
Source: bdu
Type: Configuration
Vendor: netapp inc.
Product: cloud backup
Operating System: fedora 34
{
"version_exact": "*"
}
Source: bdu
Type: Configuration
Vendor: netapp inc.
Product: cloud backup
Operating System: opensuse tumbleweed *
{
"version_exact": "*"
}
Source: bdu
Type: Configuration
Vendor: netapp inc.
Product: cloud backup
Operating System: debian gnu/linux 10
{
"version_exact": "*"
}
Source: bdu
Type: Configuration
Vendor: netapp inc.
Product: cloud backup
Operating System: strelets *
{
"version_exact": "*"
}
Source: bdu
Type: Configuration
Vendor: netapp inc.
Product: cloud backup
Operating System: осон основа оnyx *
{
"version_exact": "*"
}
Source: bdu
Type: Configuration
Vendor: netapp inc.
Product: cloud backup
Operating System: altlinux 8
{
"version_exact": "*"
}
Source: bdu
Type: Configuration
Vendor: netapp inc.
Product: cloud backup
Operating System: fedora 35
{
"version_exact": "*"
}
Source: bdu
Type: Configuration
Vendor: netapp inc.
Product: cloud backup
Operating System: debian gnu/linux 11
{
"version_exact": "*"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: strelets *
{
"version_exact": "17.1"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: debian gnu/linux 11
{
"version_exact": "17.1"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: debian gnu/linux 11
{
"version_exact": "17.2"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: fedora 35
{
"version_exact": "17.1"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: fedora 35
{
"version_exact": "17.2"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: fedora 35
{
"version_exact": "17.3"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: altlinux 8
{
"version_exact": "17.1"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: altlinux 8
{
"version_exact": "17.2"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: altlinux 8
{
"version_exact": "17.3"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: осон основа оnyx *
{
"version_exact": "17.1"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: осон основа оnyx *
{
"version_exact": "17.2"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: осон основа оnyx *
{
"version_exact": "17.3"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: opensuse tumbleweed *
{
"version_exact": "17.3"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: strelets *
{
"version_exact": "17.2"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: strelets *
{
"version_exact": "17.3"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: debian gnu/linux 10
{
"version_exact": "17.1"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: debian gnu/linux 10
{
"version_exact": "17.2"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: fedora 34
{
"version_exact": "17.3"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: fedora 34
{
"version_exact": "17.2"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: fedora 34
{
"version_exact": "17.1"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: debian gnu/linux 11
{
"version_exact": "17.3"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: opensuse tumbleweed *
{
"version_exact": "17.2"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: opensuse tumbleweed *
{
"version_exact": "17.1"
}
Source: bdu
Type: Configuration
Vendor: oracle corp.
Product: instantis enterprisetrack
Operating System: debian gnu/linux 10
{
"version_exact": "17.3"
}
Source: bdu