PT-2014-4559 · Ca · Ca Erwin Web Portal

Published

2014-04-04

·

Updated

2015-08-13

·

CVE-2014-2210

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CA ERwin Web Portal version 9.5
Description The issue allows remote attackers to obtain sensitive information, bypass intended access restrictions, cause a denial of service, or possibly execute arbitrary code. This is due to multiple directory traversal vulnerabilities.
Recommendations For CA ERwin Web Portal version 9.5, apply the necessary patches or updates to fix the directory traversal vulnerabilities. As a temporary workaround, consider restricting access to sensitive information and implementing additional access controls to minimize the risk of exploitation. Avoid using the vulnerable ConfigServiceProvider and FileAccessServiceProvider until the issue is resolved. Restrict access to the downloadScriptFile.do endpoint to minimize the risk of information disclosure. Consider disabling the ProfileIconServlet and ConfigServiceProviderServlet until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2210
ZDI-14-093
ZDI-14-094
ZDI-14-095
ZDI-14-096
ZDI-14-097

Affected Products

Ca Erwin Web Portal