CVE-2018-12469

Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
microfocusCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
microfocusenterprise_developer
𝑥
≤ 2.3
microfocusenterprise_developer
2.3:update1
microfocusenterprise_developer
2.3:update2
microfocusenterprise_developer
3.0
microfocusenterprise_developer
4.0
microfocusenterprise_developer
4.0:update1
microfocusenterprise_server
𝑥
≤ 2.3
microfocusenterprise_server
2.3:update1
microfocusenterprise_server
2.3:update2
microfocusenterprise_server
3.0
microfocusenterprise_server
4.0
microfocusenterprise_server
4.0:update1
𝑥
= Vulnerable software versions