IM
IronMonkey Threat Research

CVE-2023-5515 MEDIUM

Published: 2023-11-01 | Last Modified: 2024-11-21 | Status: Modified

Description

The responses for web queries with certain parameters disclose internal path of resources. This information can be used to learn internal structure of the application and to further plot attacks against web servers and deployed web applications.

Additional Descriptions (1)

Las respuestas a consultas web con ciertos parámetros revelan la ruta interna de los recursos. Esta información se puede utilizar para conocer la estructura interna de la aplicación y para planear más ataques contra servidores web y aplicaciones web implementadas.

CVSS Metrics

Base Score: 5.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-200
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
hitachienergy esoms * <built-in method update of dict object at 0x72a9b0e0edc0> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hitachienergy:esoms:*:*:*:*:*:*:*:*
Notification
Message here