PT-2017-13831 · Docuware+1 · Docuware Fulltext Search Server+1
Publicado
2017-11-21
·
Atualizado
2019-10-03
·
CVE-2017-15044
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DocuWare Fulltext Search server versions through 6.11
Description
The default installation of the server allows remote users to connect to and download searchable text from the embedded Solr service, bypassing access control features. An attacker can also gain privileges by modifying text. This is due to the server listening on the network interface instead of the localhost interface.
Recommendations
For versions through 6.11, reconfigure the server to listen on the localhost interface instead of the network interface to prevent unauthorized access. Additionally, consider restricting access to the Solr service to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Docuware Fulltext Search Server
Solr