Vulnerabilities > CVE-2018-10863 - Files or Directories Accessible to External Parties vulnerability in Redhat Certification 7.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL. An unauthorized attacker may use this flaw to gather sensible information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |