CVE-2017-5187
Description
A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 and earlier, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote unauthenticated attackers to view and alter (CWE-275) configuration information and inject OS commands (CWE-78) via forged requests.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| microfocus | directory_server | - | |
| microfocus | enterprise_developer | 2.3 | |
| microfocus | enterprise_server | {"endIncluding":"2.3"} | |
| microfocus | enterprise_server | 2.3 | |
| microfocus | enterprise_server_monitor_and_control | - | |
References
CWEs
CWE-352
💬 Discuss CVE-2017-5187 on VIR Community →
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.