Multiple buffer overflows in Openwsman 1.2.0 and 2.0.0 allow remote attackers to execute arbitrary code via a crafted "Authorization: Basic" HTTP header.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade libwsman1Upgrade openwsman-pythonUpgrade libwsman-develUpgrade openwsmanUpgrade openwsman-develUpgrade openwsman-clientUpgrade openwsman-rubyUpgrade openwsman-server | Feb 17, 2015 | Aug 18, 2008 |
| Vmsa 2008 0015 | — | Apply ESX350-200808413-SGApply ESXe350-200808501-I-SG | Jan 3, 2014 | Sep 18, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub