CVE-2018-12469
12.10.2018, 13:29
Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination.Enginsight
Vendor | Product | Version |
---|---|---|
microfocus | enterprise_developer | 𝑥 ≤ 2.3 |
microfocus | enterprise_developer | 2.3:update1 |
microfocus | enterprise_developer | 2.3:update2 |
microfocus | enterprise_developer | 3.0 |
microfocus | enterprise_developer | 4.0 |
microfocus | enterprise_developer | 4.0:update1 |
microfocus | enterprise_server | 𝑥 ≤ 2.3 |
microfocus | enterprise_server | 2.3:update1 |
microfocus | enterprise_server | 2.3:update2 |
microfocus | enterprise_server | 3.0 |
microfocus | enterprise_server | 4.0 |
microfocus | enterprise_server | 4.0:update1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References