CVE-2019-0094
published 2019-05-17CVE-2019-0094: Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated…
PriorityP418medium4.3CVSS 3.1
AVAACLPRNUINSUCNINAL
EPSS
0.45%
36.5th percentile
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | active_management_technology_firmware | >= 11.11.0 < 11.11.65 | 11.11.65 |
| intel | active_management_technology_firmware | >= 11.22.0 < 11.22.65 | 11.22.65 |
| intel | active_management_technology_firmware | >= 11.8.0 < 11.8.65 | 11.8.65 |
| intel | active_management_technology_firmware | >= 12.0 < 12.0.35 | 12.0.35 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6c9r-6cxc-xp3c: Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11
ghsa_unreviewed·2022-05-24
CVE-2019-0094 [LOW] CWE-20 GHSA-6c9r-6cxc-xp3c: Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.
Red Hat
struts2: ClassLoader manipulation via request parameters
vendor_redhat·2014-04-25·CVSS 5.0
CVE-2014-0112 [MEDIUM] struts2: ClassLoader manipulation via request parameters
struts2: ClassLoader manipulation via request parameters
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclus
Red Hat
struts2: ClassLoader manipulation via cookie request headers
vendor_redhat·2014-04-25·CVSS 5.0
CVE-2014-0113 [MEDIUM] struts2: ClassLoader manipulation via cookie request headers
struts2: ClassLoader manipulation via cookie request headers
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in som
Red Hat
struts2: ClassLoader manipulation via request parameters
vendor_redhat·2014-03-06·CVSS 5.0
CVE-2014-0094 [MEDIUM] struts2: ClassLoader manipulation via request parameters
struts2: ClassLoader manipulation via request parameters
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclusion was part of an import of the Google Guice repository, which includes struts2-core. Customers that build artefacts from
No detection rules found.
No public exploits indexed.
2019-05-17
Published