PT-2015-3074 · Tibbo · Tibbo Aggregate

Andrea Micalizzi

+1

·

Published

2015-11-20

·

Updated

2015-11-23

·

CVE-2015-7912

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tibbo AggreGate versions prior to 5.30.06
Description The issue is related to the lack of restrictions on file uploads in the Ice Faces module of the Tibbo AggreGate integration platform. This allows a remote attacker to upload and execute arbitrary Java code using a specially crafted XML document.
Recommendations For versions prior to 5.30.06, update to version 5.30.06 or later to resolve the issue. As a temporary workaround, consider restricting access to the upload functionality in the Ice Faces module to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00279
CVE-2015-7912
ZDI-15-571

Affected Products

Tibbo Aggregate