PT-2016-4886 · Novell · Novell Filr
W. Ettlinger
·
Publicado
2016-08-01
·
Atualizado
2017-09-03
·
CVE-2016-1608
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell Filr versions prior to 1.2 Security Update 3
Novell Filr versions 2.0 prior to Security Update 2
Description
The issue allows remote authenticated users to execute arbitrary commands via shell metacharacters in the
ntpServer parameter.Recommendations
For Novell Filr versions prior to 1.2 Security Update 3, apply Security Update 3 to resolve the issue.
For Novell Filr versions 2.0 prior to Security Update 2, apply Security Update 2 to resolve the issue.
As a temporary workaround, consider restricting access to the
ntpServer parameter to minimize the risk of exploitation.Exploit
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Novell Filr