PT-2014-4571 · Infoware · Infoware Mapsuite
Published
2014-12-01
·
Updated
2014-12-01
·
CVE-2014-2233
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Infoware MapSuite versions prior to 1.0.36
Infoware MapSuite versions 1.1.x prior to 1.1.49
Description
A server-side request forgery (SSRF) issue in the MapAPI of Infoware MapSuite allows remote attackers to trigger requests to intranet servers.
Recommendations
For versions prior to 1.0.36, update to version 1.0.36 or later.
For versions 1.1.x prior to 1.1.49, update to version 1.1.49 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infoware Mapsuite