PT-2010-2078 · Novell · Novell Access Manager
Publicado
2010-06-18
·
Atualizado
2017-08-17
·
CVE-2010-0284
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell Access Manager versions prior to 3.1.2-281
Description
The issue allows remote attackers to create arbitrary files with any contents and consequently execute arbitrary code via a .. (dot dot) in a
parameter in the getEntry method. This method is part of the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console.Recommendations
For Novell Access Manager versions prior to 3.1.2-281, update to version 3.1.2-281 or later to resolve the issue. As a temporary workaround, consider restricting access to the
getEntry method in the PortalModuleInstallManager component to minimize the risk of exploitation. Avoid using the parameter that allows the .. (dot dot) traversal in the affected servlet until the issue is resolved.Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Novell Access Manager