CVE-2019-0112
published 2019-02-18CVE-2019-0112: Improper flow control in crypto routines for Intel(R) Data Center Manager SDK before version 5.0.2 may allow a privileged user to potentially enable a denial…
PriorityP412medium4.4CVSS 3.0
AVLACLPRHUINSUCNINAH
EPSS
0.45%
36.2th percentile
Improper flow control in crypto routines for Intel(R) Data Center Manager SDK before version 5.0.2 may allow a privileged user to potentially enable a denial of service via local access.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | data_center_manager | < 5.0.2 | 5.0.2 |
CVSS provenance
nvdv3.04.4MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Intel Data Center Manager SDK
cisa_ics·2019-02-19·CVSS 8.8
[HIGH] Intel Data Center Manager SDK
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Intel Data Center Manager SDK
Last RevisedFebruary 19, 2019
Alert CodeICSA-19-050-01
## 1. EXECUTIVE SUMMARY
-
CVSS v3 8.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Intel
- Equipment: Data Center Manager SDK
- Vulnerabilities: Improper Authentication, Protection Mechanism Failure, Permission Issues, Key Management Errors, Insufficient Control Flow Management
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow escalation of privilege, denial of service, or information disclosure.
## 3. TECHNICAL DETAILS
## 3.1 AFFE
Red Hat
struts2: ClassLoader manipulation via request parameters
vendor_redhat·2014-04-25·CVSS 5.0
CVE-2014-0112 [MEDIUM] struts2: ClassLoader manipulation via request parameters
struts2: ClassLoader manipulation via request parameters
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0094.
Statement: A previous statement by Red Hat related to this CVE, prior to August 2019, said that Apache Struts 2 is not included in any Red Hat products. This earlier statement was incorrect. While Struts 2 is not actively compiled, shipped, used, or enabled in any Red Hat provided final products, and does not cause any vulnerability in the product, struts2-core jars have been included in some products' source code packages. The inclus
GHSA
GHSA-prm6-7mfp-vr8x: Improper flow control in crypto routines for Intel(R) Data Center Manager SDK before version 5
ghsa_unreviewed·2022-05-13
CVE-2019-0112 [MEDIUM] GHSA-prm6-7mfp-vr8x: Improper flow control in crypto routines for Intel(R) Data Center Manager SDK before version 5
Improper flow control in crypto routines for Intel(R) Data Center Manager SDK before version 5.0.2 may allow a privileged user to potentially enable a denial of service via local access.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/107064https://ics-cert.us-cert.gov/advisories/ICSA-19-050-01https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.htmlhttp://www.securityfocus.com/bid/107064https://ics-cert.us-cert.gov/advisories/ICSA-19-050-01https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.html
2019-02-18
Published