Vulnerability Description
The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traversal, resulting in the potential writing of files under unwanted locations, the overwriting of existing files or their deletion. This issue was addressed in Apache ODE 1.3.3 which was released in 2009, however the incorrect name CVE-2008-2370 was used on the advisory by mistake.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ode | <= 1.3.2 |
Related Weaknesses (CWE)
References
- http://mail-archives.apache.org/mod_mbox/www-announce/200908.mbox/%3Cfbdc6a97090Vendor Advisory
- https://lists.apache.org/thread.html/ce416ddfba1a87f4b8e2d8125f1c3b45d1f0b350af2
- http://mail-archives.apache.org/mod_mbox/www-announce/200908.mbox/%3Cfbdc6a97090Vendor Advisory
- https://lists.apache.org/thread.html/ce416ddfba1a87f4b8e2d8125f1c3b45d1f0b350af2
FAQ
What is CVE-2018-1316?
CVE-2018-1316 is a vulnerability with a CVSS score of 7.5 (HIGH). The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traversal, resulting in the potential writing of files un...
How severe is CVE-2018-1316?
CVE-2018-1316 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1316?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Ode.