Published:2018/10/26  Last Updated:2018/10/26

JVN#59394343
Multiple vulnerabilities in OpenDolphin

Overview

OpenDolphin contains multiple vulnerabilities.

Products Affected

  • OpenDolphin 2.7.0 and earlier

Description

OpenDolphin provided by Life Sciences Computing Corporation contains multiple vulnerabilities listed below.

  • Privilege escalation - CVE-2018-16161
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score: 8.8
    CVSS v2 AV:N/AC:L/AU:S/C:P/I:P/A:P Base Score: 6.5
  • Information disclosure (CWE-200) - CVE-2018-16162
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Base Score: 4.3
    CVSS v2 AV:N/AC:L/AU:S/C:P/I:N/A:N Base Score: 4.0
  • Restrict access permissions failure (CWE-284) - CVE-2018-16163
    CVSS v3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Base Score: 4.3
    CVSS v2 AV:N/AC:L/AU:S/C:N/I:P/A:N Base Score: 4.0

Impact

  • A user may perform unintended operations with the administrative privilege - CVE-2018-16161
  • A user may obtain other users' sensitive information such as ID and password - CVE-2018-16162
  • A user may create or delete other users - CVE-2018-16163

Solution

Update the Software
Update to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
Life Sciences Computing Corporation Vulnerable 2018/10/26 Life Sciences Computing Corporation website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Symantec Japan, Inc. Advisory Services Team reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2018-16161
CVE-2018-16162
CVE-2018-16163
JVN iPedia JVNDB-2018-000113