PT-2007-4272 · Ignite Realtime · Ignite Realtime Openfire

Publicado

2007-06-01

·

Atualizado

2008-09-10

·

CVE-2007-2975

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ignite Realtime Openfire versions 3.3.0 and earlier
Description The issue is related to the admin console in Ignite Realtime Openfire, where a filter mapping in web.xml is not properly specified. This allows remote attackers to gain privileges and execute arbitrary code by accessing functionality exposed through DWR.
Recommendations For versions 3.3.0 and earlier, consider restricting access to the admin console and DWR functionality until a proper fix is applied. As a temporary workaround, disabling DWR or limiting its exposure can help minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-2975

Produtos afetados

Ignite Realtime Openfire