Modification of Information - CVE-2015-3200

 

Modification of Information - CVE-2015-3200

Published: August 29, 2016 / Updated: October 4, 2016


Vulnerability identifier: #VU717
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3200
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to modify information on the target system.
The weakness exists due to access control flaw that allows a malicious user to obtain and modify data.
Successful exploitation of the vulnerability leads to modification of information on the vulnerable system.


Affected software

lighttpd (Alpine package)
lighttpd
IBM Integrated Management Module
Fedora

How to mitigate CVE-2015-3200


lighttpd (Alpine package) - update to 1.4.35-r4
IBM Integrated Management Module - update to 1.50
lighttpd - addressed in versions 1.4.36-1.el5, 1.4.36-1.el6, 1.4.36-1.el7, 1.4.36-1.fc21, 1.4.36-1.fc22

External References

Related Security Bulletins