PT-2013-4570 · Red Hat+1 · Jboss+1

Publicado

2013-10-11

·

Atualizado

2013-10-15

·

CVE-2013-3693

CVSS v2.0

7.9

Alta

VetorAV:A/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BlackBerry Enterprise Service (BES) versions 10.0 through 10.1.2
Description The issue concerns the BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES), which fails to properly restrict access to the JBoss Remote Method Invocation (RMI) interface. This allows remote attackers to upload and execute arbitrary packages by sending a request to port 1098.
Recommendations For versions 10.0 through 10.1.2, restrict access to the JBoss RMI interface on port 1098 to prevent remote attackers from uploading and executing arbitrary packages.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3693

Produtos afetados

Blackberry Enterprise Service
Jboss