CVE-2018-12469

I

ncorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microfocus:enterprise_developer:*:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:2.3:update1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:2.3:update2:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:3.0:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_developer:4.0:update1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:2.3:update1:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:2.3:update2:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:3.0:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:enterprise_server:4.0:update1:*:*:*:*:*:*

History

21 Nov 2024, 03:45

Type Values Removed Values Added
References () https://community.microfocus.com/microfocus/mainframe_solutions/enterprise_server/w/knowledge_base/29624/enterprise-server-security-fix-october-2018 - () https://community.microfocus.com/microfocus/mainframe_solutions/enterprise_server/w/knowledge_base/29624/enterprise-server-security-fix-october-2018 -

Information

Published : 2018-10-12 13:29

Updated : 2024-11-21 03:45


NVD link : CVE-2018-12469

Mitre link : CVE-2018-12469

CVE.ORG link : CVE-2018-12469


JSON object : View

CWE
CWE-476

NULL Pointer Dereference