PT-2013-4570 · Red Hat+1 · Jboss+1
Publicado
2013-10-11
·
Atualizado
2013-10-15
·
CVE-2013-3693
CVSS v2.0
7.9
Alta
| Vetor | AV:A/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
BlackBerry Enterprise Service (BES) versions 10.0 through 10.1.2
Description
The issue concerns the BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES), which fails to properly restrict access to the JBoss Remote Method Invocation (RMI) interface. This allows remote attackers to upload and execute arbitrary packages by sending a request to port 1098.
Recommendations
For versions 10.0 through 10.1.2, restrict access to the JBoss RMI interface on port 1098 to prevent remote attackers from uploading and executing arbitrary packages.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Blackberry Enterprise Service
Jboss