PT-2013-4847 · Imperva · Imperva Securesphere
Published
2013-06-28
·
Updated
2013-07-01
·
CVE-2013-4094
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Imperva SecureSphere version 9.0.0.5
Description
The issue allows remote authenticated users to upload executable files. This can be achieved by using the
private key or public key parameter in a T/keyManagement request to the "plain/settings.html" endpoint. For example, it is possible to upload a Linux ELF file and a shell script.Recommendations
For Imperva SecureSphere version 9.0.0.5, consider restricting access to the T/keyManagement request to prevent unauthorized file uploads until a fix is available. As a temporary workaround, restrict the use of the
private key and public key parameters in the T/keyManagement request to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imperva Securesphere