CVE-2016-4460
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://markmail.org/message/jy7o23cppny26icu
References
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.