CVE-2019-14836 Vulnerability Details

  /     /     /  

CVE-2019-14836 Metadata Quick Info

CVE Published: 26/05/2021 | CVE Updated: 05/08/2024 | CVE Year: 2019
Source: redhat | Vendor: n/a | Product: Red Hat 3scale API Management
Status : PUBLISHED

CVE-2019-14836 Description

A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An attacker could use this flaw to access unauthorized information or conduct further attacks.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Cross-Site Request Forgery (CSRF)
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).