PT-2018-4020 · Apache · Apache Juddi
Marc Schoenefeld
·
Publicado
2018-02-19
·
Atualizado
2018-03-18
·
CVE-2009-4267
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apache jUDDI version 3.0.0
Description
The issue concerns the console in Apache jUDDI, which fails to properly escape line feeds. This allows remote authenticated users to spoof log entries by manipulating the
numRows parameter.Recommendations
For Apache jUDDI version 3.0.0, consider restricting access to the console until a proper fix is available, and avoid using the
numRows parameter in a way that could facilitate log entry spoofing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Encoding or Escaping of Output
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Juddi