CVE-2019-17087 Vulnerability Details

  /     /     /  

CVE-2019-17087 Metadata Quick Info

CVE Published: 11/12/2019 | CVE Updated: 05/08/2024 | CVE Year: 2019
Source: microfocus | Vendor: Micro Focus International | Product: AcuToWeb
Status : PUBLISHED

CVE-2019-17087 Description

Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be exploited to enumerate and download files from the filesystem of the system running AcuToWeb, with the privileges of the account AcuToWeb is running under.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Unauthorized file download.
Source: Micro Focus International

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).