PT-2019-12446 · Oneshield · Oneshield Policy
Ghost
+1
·
Publicado
2019-05-08
·
Atualizado
2020-08-24
·
CVE-2019-11642
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OneShield Policy (Dragon Core) versions prior to 5.1.10
Description
A log poisoning issue has been found, allowing authenticated remote adversaries to poison log files by entering malicious payloads in either headers or form elements, which are then executed via a client-side debugging console. This issue is dependent on the debugging console and Java Bean being accessible to the deployed application.
Recommendations
For versions prior to 5.1.10, update to version 5.1.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the debugging console and Java Bean to minimize the risk of exploitation.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Oneshield Policy