570
VMScore

CVE-2016-2171

Published: 11/04/2016 Updated: 14/04/2016
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The User Manager service in Apache Jetspeed prior to 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote malicious users to (1) add, (2) edit, or (3) delete users via the REST API.

Vulnerable Product Search on Vulmon Subscribe to Product

apache jetspeed