CVE-2015-2896: Infoleak
Published Dec 31, 2015
·Updated
The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, and event-log information via a command.
Affected Software
1 affected component
IDERA Uptime Infrastructure Monitor<=7.6
Event History
Dec 31, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2896?
CVE-2015-2896 has a medium severity rating due to its potential for information disclosure.
2
How do I fix CVE-2015-2896?
To fix CVE-2015-2896, upgrade to Idera Uptime Infrastructure Monitor version 7.7 or later.
3
What types of information can be disclosed by CVE-2015-2896?
CVE-2015-2896 allows remote attackers to access sensitive information such as version, OS, process, and event-log details.
4
Who is affected by CVE-2015-2896?
Any user of Idera Uptime Infrastructure Monitor versions up to and including 7.6 is affected by CVE-2015-2896.
5
Is CVE-2015-2896 a remote vulnerability?
Yes, CVE-2015-2896 can be exploited by remote attackers to gather sensitive system information.