« Volver al listado

CVE-2018-14863

Estado: ModificadaAlta (8.1)—

Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-14863",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-07-03T19:15:10.643",
  "references": [
    {
      "url": "https://github.com/odoo/odoo/issues/32508",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/odoo/odoo/issues/32508",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC."
    },
    {
      "lang": "es",
      "value": "El control de acceso incorrecto en el marco de RPC en Odoo Community 8.0 a 11.0 y Odoo Enterprise 9.0 a 11.0 permite a los usuarios identificados llamar a funciones privadas a través de RPC."
    }
  ],
  "lastModified": "2026-06-17T01:41:46.937",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:odoo:odoo:9.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3F9E8F1-FAF7-44AE-8D05-BE717D247EDE"
            },
            {
              "criteria": "cpe:2.3:a:odoo:odoo:9.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "167C709E-C8B2-4CCB-963E-E1D8C664190A"
            },
            {
              "criteria": "cpe:2.3:a:odoo:odoo:10.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C52F2EEB-11E5-49E8-AD06-3014FF2C2D24"
            },
            {
              "criteria": "cpe:2.3:a:odoo:odoo:10.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4405E54-6C16-49D5-B632-3D72091B2FEB"
            },
            {
              "criteria": "cpe:2.3:a:odoo:odoo:11.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38424B03-4121-4A79-8E4E-4CB4DCD3E4A5"
            },
            {
              "criteria": "cpe:2.3:a:odoo:odoo:11.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1298CF62-A06E-48AD-8141-0541DE3F6381"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}