CVE-2014-3526

EUVD-2022-4914
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Affected Products (NVD)
VendorProductVersion
apachewicket
1.5.0 ≤
𝑥
< 1.5.12
apachewicket
6.0.0
apachewicket
6.0.0:beta1
apachewicket
6.0.0:beta2
apachewicket
6.0.0:beta3
apachewicket
6.1.0
apachewicket
6.1.1
apachewicket
6.2.0
apachewicket
6.3.0
apachewicket
6.4.0
apachewicket
6.5.0
apachewicket
6.6.0
apachewicket
6.7.0
apachewicket
6.8.0
apachewicket
6.9.0
apachewicket
6.9.1
apachewicket
6.10.0
apachewicket
6.11.0
apachewicket
6.12.0
apachewicket
6.13.0
apachewicket
6.14.0
apachewicket
6.15.0
apachewicket
6.16.0
apachewicket
7.0.0
apachewicket
7.0.0:milestone1
apachewicket
7.0.0:milestone2
𝑥
= Vulnerable software versions