« Volver al listado

CVE-2008-2318

Estado: ModificadaMedia (5)—

The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-2318",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-07-14T18:41:00.000",
  "references": [
    {
      "url": "http://lists.apple.com/archives/security-announce//2008/Jul/msg00002.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31060",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.apple.com/kb/HT2352",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/30191",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1020473",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2093/references",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43735",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce//2008/Jul/msg00002.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/31060",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.apple.com/kb/HT2352",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30191",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1020473",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2093/references",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43735",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs."
    },
    {
      "lang": "es",
      "value": "La implementación WOHyperlink de WebObjects de Apple Xcode tools anterior a 3.1 , añade los IDs de sesiones locales a URLs no generadas en local, esto permite a atacantes remotos obtener información potencialmente sensible leyendo las solicitudes de estas URLs."
    }
  ],
  "lastModified": "2026-06-16T22:53:32.380",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:xcode:1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B66C7172-0104-41B7-8291-62B7E72B3AEE"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode:2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56E8F424-A343-414E-BA02-F70B20DE101A"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD352A40-6418-4B0A-83E4-9A2BFFED2328",
              "versionEndIncluding": "3.0"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54AC4EC4-B812-441D-B96D-51D713A99C93"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34B7CE28-9AC7-492D-8544-1E69100E7C19"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89F1A293-BD40-4C49-B162-B2EDF804DB01"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5C480CA-0D92-4BC5-9C40-BB1F6B35F12F"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3F383E8-F88B-4FFC-8C3A-3F92AB5DE662"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A155A7B8-F502-4FB3-8C8E-3802713F325B"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:2.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FDE331D0-B883-4D87-8499-6EEE8C6792DF"
            },
            {
              "criteria": "cpe:2.3:a:apple:xcode_tools:2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B198F65-77F2-4FD5-AE3F-3FC2C423F154"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}