PT-2017-3369 · Progress · Openedge

Publicado

2017-10-31

·

Atualizado

2017-11-22

·

CVE-2015-9245

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Progress Software OpenEdge versions 10.2x through 11.x
Description The issue is related to an insecure default configuration that lacks proper access control, allowing unauthenticated remote attackers to load and execute malicious Java classes by specifying arbitrary URLs via port 20931. This can be exploited by a remote attacker using specially crafted URL addresses.
Recommendations For Progress Software OpenEdge versions 10.2x through 11.x, consider restricting access to port 20931 as a temporary workaround until a proper fix is available. Additionally, review and modify the default configuration to enforce proper access controls and prevent the execution of malicious Java classes.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00140
CVE-2015-9245

Produtos afetados

Openedge