PT-2017-13831 · Docuware+1 · Docuware Fulltext Search Server+1

Publicado

2017-11-21

·

Atualizado

2019-10-03

·

CVE-2017-15044

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DocuWare Fulltext Search server versions through 6.11
Description The default installation of the server allows remote users to connect to and download searchable text from the embedded Solr service, bypassing access control features. An attacker can also gain privileges by modifying text. This is due to the server listening on the network interface instead of the localhost interface.
Recommendations For versions through 6.11, reconfigure the server to listen on the localhost interface instead of the network interface to prevent unauthorized access. Additionally, consider restricting access to the Solr service to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-15044

Produtos afetados

Docuware Fulltext Search Server
Solr