HIGH · 10.0

CVE-2013-5912

VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action.

Vulnerability Description

VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ThomsonreutersVelocity Analytics Vhayu Analytic Server6.94

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-5912?

CVE-2013-5912 is a vulnerability with a CVSS score of 10.0 (HIGH). VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action.

How severe is CVE-2013-5912?

CVE-2013-5912 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-5912?

Check the references section above for vendor advisories and patch information. Affected products include: Thomsonreuters Velocity Analytics Vhayu Analytic Server.