PT-2018-4088 · Apache+1 · Axis+1

Publicado

2018-05-24

·

Atualizado

2018-06-28

·

CVE-2013-3018

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Application Dependency Discovery Manager (TADDM) versions 7.1.2 through 7.2.1.4
Description The issue allows remote attackers to obtain sensitive configuration information via a direct request. This is demonstrated by accessing the happyaxis.jsp page in the AXIS webapp.
Recommendations For versions 7.1.2 through 7.2.1.4, restrict access to the happyaxis.jsp page to minimize the risk of exploitation. Consider disabling the AXIS webapp in deploy-tomcat/axis until a fix is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3018

Produtos afetados

Axis
Ibm Tivoli Application Dependency Discovery Manager