CVE-2016-4813
high
CVSS v3
8.8
CVSS v2
9.0
VIR risk
8.8
Description
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: vultures@jpcert.or.jp — http://www.netcommons.org/muer4mz6s-6669
Vendor advisory: vultures@jpcert.or.jp — http://jvndb.jvn.jp/jvndb/JVNDB-2016-000075
Vendor advisory: vultures@jpcert.or.jp — http://jvn.jp/en/jp/JVN00460236/index.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| netcommons | netcommons | {"endIncluding":"2.4.2.1"} | |
References
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.