An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain unauthorized access to the WhatsUp Gold system, (2) obtain information about the WhatsUp Gold system, or (3) execute remote commands.
Metrics
Affected Vendors & Products
References
History
Tue, 27 Aug 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Progress
Progress whatsup Gold |
|
CPEs | cpe:2.3:a:progress:whatsup_gold:*:*:*:*:*:*:*:* | |
Vendors & Products |
Ipswitch
Ipswitch whatsup Gold |
Progress
Progress whatsup Gold |
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-05-01T16:00:00
Updated: 2024-08-05T07:10:47.096Z
Reserved: 2018-03-22T00:00:00
Link: CVE-2018-8939
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-05-01T16:29:00.507
Modified: 2024-11-21T04:14:38.980
Link: CVE-2018-8939
Redhat
No data.