Published on August 25th, 2019 📆 | 3479 Views ⚑


openITCOCKPIT up to 3.7.0 Code Injection privilege escalation

A vulnerability was found in openITCOCKPIT up to 3.7.0 and classified as critical. This issue affects an unknown functionality. The manipulation with an unknown input leads to a privilege escalation vulnerability (Code Injection). Using CWE to declare the problem leads to CWE-94. Impacted is confidentiality, integrity, and availability.

The weakness was shared 08/23/2019. The identification of this vulnerability is CVE-2019-15490 since 08/22/2019. Neither technical details nor an exploit are publicly available.

Upgrading to version 3.7.1 eliminates this vulnerability.

The entries 140733, 140732, 140731 and 140730 are related to this item.


Class: Privilege escalation / Code Injection (CWE-94)
Local: Yes
Remote: No

Status: Not defined

Threat Intelligenceinfoedit

Upgrade: openITCOCKPIT 3.7.1

08/22/2019 CVE assigned
08/23/2019 +1 days Advisory disclosed
08/24/2019 +1 days VulDB entry created
08/24/2019 +0 days VulDB last update
