PT-2009-3965 · A A S · Application Access Server
Felipe Aragon
·
Publicado
2009-05-14
·
Atualizado
2018-10-10
·
CVE-2009-1464
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Application Access Server (A-A-S) version 2.0.48
Description
The issue allows remote attackers to hijack the authentication of administrators for requests, including executing arbitrary programs via a command job, stopping services via a setservice job, or terminating processes via a killprocess job.
Recommendations
For Application Access Server (A-A-S) version 2.0.48, consider disabling the
index.aas module until a patch is available to prevent exploitation of the CSRF vulnerabilities. Restrict access to the setservice, killprocess, and command jobs to minimize the risk of unauthorized execution.Exploit
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Application Access Server