PT-2012-3572 · Autoform · Autoform Pdm Archive
David Elze
·
Publicado
2012-06-13
·
Atualizado
2012-09-29
·
CVE-2012-1827
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AutoFORM PDM Archive versions prior to 7.1
Description
The issue concerns a lack of authorization requirements in the web service of the affected software. This allows remote authenticated users to perform database operations via a SOAP request. For example, this can be achieved through the "initializeQueryDatabase2" request.
Recommendations
For versions prior to 7.1, consider restricting access to the web service to minimize the risk of unauthorized database operations until a patch is available. As a temporary workaround, limit the ability to perform database operations via SOAP requests to only necessary users.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Autoform Pdm Archive