CVE-2017-7552
A flaw was discovered in the file editor of millicore which allows files to be executed as well as created. An attacker could use this flaw to compromise other users or teams projects stored in source control management of the RHMAP Core installation.
Find out more about CVE-2017-7552 from the MITRE CVE dictionary dictionary and NIST NVD.
CVSS v3 metrics
| CVSS3 Base Score | 7.5 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:H |
| Attack Vector | Adjacent Network |
| Attack Complexity | High |
| Privileges Required | High |
| User Interaction | None |
| Scope | Changed |
| Confidentiality | High |
| Integrity Impact | Low |
| Availability Impact | High |
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Mobile Application Platform 4.5 | RHSA-2017:2674 | 2017-09-18 |
| Red Hat Mobile Application Platform 4.5 | RHSA-2017:2675 | 2017-09-18 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat Mobile Application Platform On-Premise 4 | fh-scm | Will not fix |
