AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-2171

HIGH · CVSS 7.5 EPSS 42.67%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-04-11 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-2171
Severity
HIGH
CVSS
7.5
EPSS
42.67%
Apache

Original NVD Description

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.