CVE Vulnerabilities

CVE-2017-11467

Improper Privilege Management

Published: Jul 20, 2017 | Modified: Oct 03, 2019
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

OrientDB through 2.2.22 does not enforce privilege requirements during where or fetchplan or order by use, which allows remote attackers to execute arbitrary OS commands via a crafted request.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Orientdb Orientdb * 2.2.22 (including)

Potential Mitigations

References