CVE-2016-3002
published 2016-11-30CVE-2016-3002: IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached…
PriorityP45low2.1CVSS 3.0
AVPACLPRLUINSUCLINAN
EPSS
0.33%
25.7th percentile
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | connections | — | — |
| ibm | connections | — | — |
| ibm | connections | — | — |
| saltstack | salt | >= 2016.11.0 < 3003rc1 | 3003rc1 |
CVSS provenance
nvdv3.02.1LOWCVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Command Injection in SaltStack Salt
ghsa·2022-05-24
CVE-2021-31607 [HIGH] CWE-77 Command Injection in SaltStack Salt
Command Injection in SaltStack Salt
In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).
GHSA
GHSA-393m-vg99-2x36: IBM Connections 4
ghsa_unreviewed·2022-05-17
CVE-2016-3002 [LOW] CWE-200 GHSA-393m-vg99-2x36: IBM Connections 4
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 allows physically proximate attackers to obtain sensitive information by reading cached data on a client device.
Red Hat
salt: Command injection in the snapper module
vendor_redhat·2021-04-23·CVSS 7.8
CVE-2021-31607 [HIGH] CWE-77 salt: Command injection in the snapper module
salt: Command injection in the snapper module
In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).
A flaw was found in Salt. A command injection vulnerability occurs in the snapper module that allows local privilege escalation on a minion. This attack requires the creation of a file with a pathname that is backed up by snapper, with the master calling the snapper.diff function. Snapper.diff executes the popen unsafely. The highest threat from this vulnerability is to confidentiality, integrity, as well as system
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1LO90039http://www-01.ibm.com/support/docview.wss?uid=swg21990864http://www.securityfocus.com/bid/94331http://www-01.ibm.com/support/docview.wss?uid=swg1LO90039http://www-01.ibm.com/support/docview.wss?uid=swg21990864http://www.securityfocus.com/bid/94331
2016-11-30
Published