PT-2019-15756 · Titanhq+1 · Webtitan+1

Publicado

2019-12-02

·

Atualizado

2019-12-06

·

CVE-2019-19015

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TitanHQ WebTitan versions prior to 5.18
Description An issue in the proxy service of TitanHQ WebTitan allows connections to the internal PostgreSQL database without password authentication, enabling an attacker to fully control the appliance database. This access can lead to further exploitation, including code execution.
Recommendations For versions prior to 5.18, update to version 5.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy service to minimize the risk of exploitation.

Exploit

Correção

Exposure of Resource to Wrong Sphere

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19015

Produtos afetados

Postgresql
Webtitan