PT-2013-2226 · Red Hat · Jboss Enterprise Portal Platform

Nick Scavelli

·

Publicado

2013-04-12

·

Atualizado

2013-04-15

·

CVE-2013-0314

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JBoss Enterprise Portal Platform version 5.2.2
Description The issue concerns the GateIn Portal export/import gadget, which fails to properly check authentication when importing Zip files. This allows remote attackers to modify site contents, remove the site, or alter the access controls for portlets.
Recommendations For JBoss Enterprise Portal Platform version 5.2.2, consider restricting access to the import functionality of the GateIn Portal export/import gadget until a proper fix is available, to minimize the risk of unauthorized modifications to site contents or access controls.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-0314

Produtos afetados

Jboss Enterprise Portal Platform