PT-2017-3369 · Progress · Openedge
Publicado
2017-10-31
·
Atualizado
2017-11-22
·
CVE-2015-9245
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Progress Software OpenEdge versions 10.2x through 11.x
Description
The issue is related to an insecure default configuration that lacks proper access control, allowing unauthenticated remote attackers to load and execute malicious Java classes by specifying arbitrary URLs via port 20931. This can be exploited by a remote attacker using specially crafted URL addresses.
Recommendations
For Progress Software OpenEdge versions 10.2x through 11.x, consider restricting access to port 20931 as a temporary workaround until a proper fix is available. Additionally, review and modify the default configuration to enforce proper access controls and prevent the execution of malicious Java classes.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openedge