CVE-2021-45968
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.
7.5
CVSS
10.4%
EPSS (exploit prob.)
96th
EPSS percentile
2022-03-18
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-918
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| jivesoftware | jive | all versions |
| pascom | cloud_phone_system | <= 7.19 |
Check a specific version with /api/v1/cve/match.
References
- https://jivesoftware.com/platform/
- https://kerbit.io/research/read/blog/4
- https://tutorialboy24.blogspot.com/2022/03/the-story-of-3-bugs-that-lead-to.html
- https://www.pascom.net/doc/en/release-notes/
- https://www.pascom.net/doc/en/release-notes/pascom19/
- https://jivesoftware.com/platform/
- https://kerbit.io/research/read/blog/4
- https://tutorialboy24.blogspot.com/2022/03/the-story-of-3-bugs-that-lead-to.html
- https://www.pascom.net/doc/en/release-notes/
- https://www.pascom.net/doc/en/release-notes/pascom19/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-45968