CVE-2020-1952 Vulnerability Details
/
/
/
CVE-2020-1952 Metadata Quick Info
CVE Published: 27/04/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020
Source: apache |
Vendor: Apache |
Product: IoTDB
Status : PUBLISHED
CVE-2020-1952 Description
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: Information Disclosure
Source: Apache
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).