PT-2017-14474 · Netgain Systems · Netgain Systems Enterprise Manager

Rgod

·

Publicado

2017-12-13

·

Atualizado

2019-10-09

·

CVE-2017-16590

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetGain Systems Enterprise Manager version 7.2.699 build 1001
Description This issue allows remote attackers to bypass authentication on vulnerable installations. User interaction is required to exploit this issue. The specific flaw exists within the MainFilter servlet, resulting from the lack of proper string matching inside the doFilter method. An attacker can leverage this in conjunction with other issues to execute arbitrary code in the context of Administrator.
Recommendations For NetGain Systems Enterprise Manager version 7.2.699 build 1001, consider disabling the doFilter method within the MainFilter servlet as a temporary workaround until a patch is available. Restrict access to the MainFilter servlet to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16590
ZDI-17-955

Produtos afetados

Netgain Systems Enterprise Manager