CVE-2018-2469
published 2018-10-09CVE-2018-2469: Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise be…
PriorityP342high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.73%
74.9th percentile
Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise be restricted.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| sap | adaptive_server_enterprise | — | — |
| sap | adaptive_server_enterprise | — | — |
| sap | sap_adaptive_server_enterprise | — | — |
| sap | sap_adaptive_server_enterprise | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_apache9.8
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6v36-q94p-qrcw: Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15
ghsa_unreviewed·2022-05-13
CVE-2018-2469 [HIGH] GHSA-6v36-q94p-qrcw: Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15
Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise be restricted.
Apache
Apache nifi: CVE-2018-1310
vendor_apache·CVSS 9.8
CVE-2018-1310 Apache nifi: CVE-2018-1310
Apache nifi: CVE-2018-1310
Title: Potential Denial of Service in JMS Processors Published: 2018-04-08 Severity: Medium Products: Apache NiFi Affected Versions: 0.1.0 to 1.5.0 Fixed Versions: 1.6.0 Reporter: 圆珠笔 References CVE Record: CVE-2018-1310 NVD Record: CVE-2018-1310 Apache Jira Issue: NIFI-4870 GitHub Pull Request: 2469 Malicious JMS content could cause denial of service in impacted Processors. See ActiveMQ CVE-2015-5254 announcement for more information. NiFi 1.6.0 upgrades the activemq-client library to 5.15.3. Users running a prior release should upgrade to 1.6.0.
Severity: moderate
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/105526https://launchpad.support.sap.com/#/notes/2679789https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=500633095http://www.securityfocus.com/bid/105526https://launchpad.support.sap.com/#/notes/2679789https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=500633095
2018-10-09
Published