Vulnerability Description
Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microfocus | Enterprise Developer | <= 2.3 |
| Microfocus | Enterprise Server | <= 2.3 |
Related Weaknesses (CWE)
References
- https://community.microfocus.com/microfocus/mainframe_solutions/enterprise_serve
- https://community.microfocus.com/microfocus/mainframe_solutions/enterprise_serve
FAQ
What is CVE-2018-12469?
CVE-2018-12469 is a vulnerability with a CVSS score of 7.5 (HIGH). Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Upd...
How severe is CVE-2018-12469?
CVE-2018-12469 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12469?
Check the references section above for vendor advisories and patch information. Affected products include: Microfocus Enterprise Developer, Microfocus Enterprise Server.