CVE ID | CVE-2017-16607 |
CVSS SCORE | 5.0, AV:N/AC:L/Au:N/C:P/I:N/A:N |
AFFECTED VENDORS |
NetGain Systems |
AFFECTED PRODUCTS |
Enterprise Manager |
VULNERABILITY DETAILS |
The specific flaw exists within heapdumps.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to download heap memory dump. An attacker can leverage this in conjunction with other vulnerabilities to disclose sensitive information in the context of the current process. |
ADDITIONAL DETAILS |
|
DISCLOSURE TIMELINE |
|
CREDIT | Jacob Baines - Tenable Network Security |