PT-2015-3074 · Tibbo · Tibbo Aggregate

Andrea Micalizzi

+1

·

Publicado

2015-11-20

·

Atualizado

2015-11-23

·

CVE-2015-7912

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tibbo AggreGate versions prior to 5.30.06
Description The issue is related to the lack of restrictions on file uploads in the Ice Faces module of the Tibbo AggreGate integration platform. This allows a remote attacker to upload and execute arbitrary Java code using a specially crafted XML document.
Recommendations For versions prior to 5.30.06, update to version 5.30.06 or later to resolve the issue. As a temporary workaround, consider restricting access to the upload functionality in the Ice Faces module to minimize the risk of exploitation.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00279
CVE-2015-7912
ZDI-15-571

Produtos afetados

Tibbo Aggregate