AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-17891

LOW · CVSS 3.7 EPSS 0.73%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-10-04 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-17891
Severity
LOW
CVSS
3.7
EPSS
0.73%
Windows Oracle

Original NVD Description

Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP 500 error, leaking technical information an attacker could use to initiate a more elaborate attack.