PT-2015-7667 · Tibbo+1 · Tibbo Aggregate+1

Andrea Micalizzi

+1

·

Publicado

2015-11-20

·

Atualizado

2015-11-23

·

CVE-2015-7913

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tibbo AggreGate versions prior to 5.30.06
Description The issue allows local users to execute arbitrary Java code with SYSTEM privileges. This is achieved by using the Apache Axis AdminService deployment method to publish a class.
Recommendations For versions prior to 5.30.06, update to version 5.30.06 or later to resolve the issue. As a temporary workaround, consider restricting access to the Apache Axis AdminService to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2015-7913
ZDI-15-572

Produtos afetados

Apache Axis
Tibbo Aggregate