PT-2007-4272 · Ignite Realtime · Ignite Realtime Openfire
Publicado
2007-06-01
·
Atualizado
2008-09-10
·
CVE-2007-2975
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ignite Realtime Openfire versions 3.3.0 and earlier
Description
The issue is related to the admin console in Ignite Realtime Openfire, where a filter mapping in web.xml is not properly specified. This allows remote attackers to gain privileges and execute arbitrary code by accessing functionality exposed through DWR.
Recommendations
For versions 3.3.0 and earlier, consider restricting access to the admin console and DWR functionality until a proper fix is applied. As a temporary workaround, disabling DWR or limiting its exposure can help minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ignite Realtime Openfire