CVE-2014-3526

Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
apachewicket
1.5.0 ≤
𝑥
< 1.5.12
apachewicket
6.0.0
apachewicket
6.0.0:beta1
apachewicket
6.0.0:beta2
apachewicket
6.0.0:beta3
apachewicket
6.1.0
apachewicket
6.1.1
apachewicket
6.2.0
apachewicket
6.3.0
apachewicket
6.4.0
apachewicket
6.5.0
apachewicket
6.6.0
apachewicket
6.7.0
apachewicket
6.8.0
apachewicket
6.9.0
apachewicket
6.9.1
apachewicket
6.10.0
apachewicket
6.11.0
apachewicket
6.12.0
apachewicket
6.13.0
apachewicket
6.14.0
apachewicket
6.15.0
apachewicket
6.16.0
apachewicket
7.0.0
apachewicket
7.0.0:milestone1
apachewicket
7.0.0:milestone2
𝑥
= Vulnerable software versions