PT-2018-4020 · Apache · Apache Juddi

Marc Schoenefeld

·

Publicado

2018-02-19

·

Atualizado

2018-03-18

·

CVE-2009-4267

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apache jUDDI version 3.0.0
Description The issue concerns the console in Apache jUDDI, which fails to properly escape line feeds. This allows remote authenticated users to spoof log entries by manipulating the numRows parameter.
Recommendations For Apache jUDDI version 3.0.0, consider restricting access to the console until a proper fix is available, and avoid using the numRows parameter in a way that could facilitate log entry spoofing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Encoding or Escaping of Output

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4267

Produtos afetados

Apache Juddi