Vulnerability Description
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Hybris | >= 5.0.0, <= 5.0.0.3 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/130444/Hybris-Commerce-Software-Suite-5.x-FExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2015/Feb/63ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/534722/100/1600/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/72681Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/130444/Hybris-Commerce-Software-Suite-5.x-FExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2015/Feb/63ExploitMailing ListThird Party Advisory
- http://www.securityfocus.com/archive/1/534722/100/1600/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/72681Third Party AdvisoryVDB Entry
FAQ
What is CVE-2014-8871?
CVE-2014-8871 is a vulnerability with a CVSS score of 7.5 (HIGH). Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5....
How severe is CVE-2014-8871?
CVE-2014-8871 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8871?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Hybris.