« Volver al listado

CVE-2011-5157

Estado: ModificadaMedia (6.9)—

Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-5157",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-09-06T10:41:58.613",
  "references": [
    {
      "url": "http://secunia.com/advisories/46692",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.attachmate.com/techdocs/1708.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/50496",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78318",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/46692",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.attachmate.com/techdocs/1708.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/50496",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/78318",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad que no se confía en la ruta de búsqueda de Attachmate Reflection anterior a v14.1 SP1 permite a usuarios locales obtener privilegios a través de un troyano DLL en el directorio de trabajo actual, un tema relacionado con CVE-2011-0107. NOTA: algunos de estos detalles han sido obtenidos a partir de información de terceros."
    }
  ],
  "lastModified": "2026-06-16T23:36:03.303",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_for_hp:14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6020EBC1-CA7D-4803-ADB0-C63BE3E3D200"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_for_hp:14.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A781A22A-62D6-4217-8C3F-0A9EC89B8640"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_for_ibm:14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0964E14-E220-4569-B3E1-62246B2C6DD2"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_for_ibm:14.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C23832D4-4E10-4CCD-9D1E-F7B7279F8547"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_for_regis_graphics_server:14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A783A8DF-4BE3-44E7-8DB0-8FA7A3A57D59"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_for_regis_graphics_server:14.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98BE33BA-CDB3-42DA-AE9D-E1B555EF08A8"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_for_unix_and_openvms:14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7E9B277-E099-4331-A606-E2AB6D8D5BEF"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_for_unix_and_openvms:14.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BABA1BE4-D92F-4D63-85C4-4C9B5F636585"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_x:14.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8172ABBD-DE47-4E57-B379-6D7D987DE601"
            },
            {
              "criteria": "cpe:2.3:a:attachmate:reflection_x:14.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB5221FF-2A62-424C-AFB7-BB2168A41BFF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/426.html\r\n\r\n'CWE-426 Untrusted Search Path'",
  "sourceIdentifier": "cve@mitre.org"
}