« Volver al listado

CVE-2017-7681

Estado: ModificadaAlta (8.8)—

Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-7681",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@apache.org",
      "affectedData": [
        {
          "vendor": "Apache Software Foundation",
          "product": "Apache OpenMeetings",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-07-17T13:18:29.877",
  "references": [
    {
      "url": "http://markmail.org/message/j774dp5ro5xmkmg6",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "security@apache.org"
    },
    {
      "url": "http://markmail.org/message/j774dp5ro5xmkmg6",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the existing query and leak the structure of other queries being made by the application in the back-end."
    },
    {
      "lang": "es",
      "value": "Apache OpenMeetings versión 1.0.0.0,  es vulnerable a la inyección SQL. Esto permite a usuarios identificados modificar la estructura de la consulta existente y filtrar la estructura de otras consultas que están siendo realizadas por la aplicación en el back-end."
    }
  ],
  "lastModified": "2026-06-17T01:24:58.510",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72B6167B-E822-4146-87F2-E2769DC85F99"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CDA54EE-9AE1-4551-8C24-D2077515029C"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB137AFF-1BB8-4FFC-9247-376718AAFEB2"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E8B4E9B-D707-4B96-93B0-7E5F19C8C9A9"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E44AAC6C-13E1-423B-BB4C-4C92B763DE34"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "268D5F6C-F1E8-400B-8D79-A79A9481DFDE"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57895052-DBEF-4CD4-B2B8-C6EBB7A607C8"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA80F112-8C3B-4D79-86A6-C7B3396C4DDB"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5AC28AE2-7EDD-4554-B418-7C4AD5D6E943"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94BB2711-23CA-4FA5-8868-664A839F7EAA"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FCA799EE-CDF8-41C6-A3CF-5FC47ED0920C"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96D13854-BD10-4404-89A7-F6D398680628"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EC465AB-5CA6-4C97-8544-59D3236A7123"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FCC94CB-EBC7-46D2-BD9E-DB043A4CD5B1"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC811824-EA8F-49F6-B732-10731A1BC0EF"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AFF29DC-46BA-4505-A921-42C783BC4C8F"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "085A80B3-B880-428D-AF1D-BED61C31E304"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46036494-F97D-4C02-A630-102D9E7DE2CE"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2C208B6-E86A-4F73-B078-BA47BA1B162D"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "331EDEB7-D823-43C6-9D8B-E872F921A328"
            },
            {
              "criteria": "cpe:2.3:a:apache:openmeetings:3.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8D44A5F-C7BD-4CC2-9065-179FA92301C9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@apache.org"
}