PT-2012-3572 · Autoform · Autoform Pdm Archive

David Elze

·

Publicado

2012-06-13

·

Atualizado

2012-09-29

·

CVE-2012-1827

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AutoFORM PDM Archive versions prior to 7.1
Description The issue concerns a lack of authorization requirements in the web service of the affected software. This allows remote authenticated users to perform database operations via a SOAP request. For example, this can be achieved through the "initializeQueryDatabase2" request.
Recommendations For versions prior to 7.1, consider restricting access to the web service to minimize the risk of unauthorized database operations until a patch is available. As a temporary workaround, limit the ability to perform database operations via SOAP requests to only necessary users.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1827

Produtos afetados

Autoform Pdm Archive