CVE-2017-7553
The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources and access restricted endpoints.
Find out more about CVE-2017-7553 from the MITRE CVE dictionary dictionary and NIST NVD.
CVSS v3 metrics
| CVSS3 Base Score | 6 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L |
| Attack Vector | Network |
| Attack Complexity | High |
| Privileges Required | Low |
| User Interaction | None |
| Scope | Changed |
| Confidentiality | Low |
| Integrity Impact | Low |
| Availability Impact | Low |
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat Mobile Application Platform 4.5 | RHSA-2017:2674 | 2017-09-18 |
| Red Hat Mobile Application Platform 4.5 | RHSA-2017:2675 | 2017-09-18 |
Affected Packages State
| Platform | Package | State |
|---|---|---|
| Red Hat Mobile Application Platform On-Premise 4 | millicore | Will not fix |
