CVE-2009-4267

MEDIUM

Apache jUDDI 3.0.0 - Authenticated Log Spoofing via Console numRows Parameter

Title source: llm
STIX 2.1

Description

The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0145
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-116
Status published
Products (1)
apache/juddi 3.0.0
Published Feb 19, 2018
Tracked Since Feb 18, 2026