5.5
CVSSv2

CVE-2014-2332

Published: 31/08/2015 Updated: 01/09/2015
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:P

Vulnerability Summary

Check_MK prior to 1.2.2p3 and 1.2.3x prior to 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, related to "Insecure Direct Object References." NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2330.

Vulnerable Product Search on Vulmon Subscribe to Product

check mk project check mk

Vendor Advisories

Debian Bug report logs - #742689 check-mk: CVE-2014-2329, CVE-2014-2330, CVE-2014-2331, CVE-2014-2332 Package: check-mk; Maintainer for check-mk is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 26 Mar 2014 12:36:06 UTC Severity: ...