Aller au contenu

Fiche vulnérabilité

CVE-2023-3349 : faille élevée ayesa ibermatica rps (CVSS 7.5)

Description

Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, such as usernames, IP addresses or SQL queries sent to the application. By accessing the URL /RPS2019Service/status.html, the application enables the logging mechanism by generating the log file, which can be downloaded.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
3 oct. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • ayesa ibermatica rps

Références

Rechercher une autre vulnérabilité dans la base CVE