CVE-2016-0710 describes multiple SQL injection vulnerabilities in the User Manager service of Apache Jetspeed versions prior to 2.3.1. Attackers can exploit these flaws by manipulating the 'role' or 'user' parameters in requests to services/usermanager/users/, enabling arbitrary SQL command execution. This vulnerability carries a CVSSv3 score of 8.8 (HIGH), indicating a network-exploitable flaw with low attack complexity, requiring only low privileges, and leading to high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, its high EPSS score suggests a significant likelihood of exploitation, and exploit code for a related arbitrary file upload vulnerability exists in Metasploit, though direct SQLi exploit code is not explicitly mentioned.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.0CPE matchmatch criteria | cpe:2.3:a:apache:jetspeed:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.