PT-2017-13831 · Docuware+1 · Docuware Fulltext Search Server+1
Published
2017-11-21
·
Updated
2019-10-03
·
CVE-2017-15044
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DocuWare Fulltext Search server versions through 6.11
Description
The default installation of the server allows remote users to connect to and download searchable text from the embedded Solr service, bypassing access control features. An attacker can also gain privileges by modifying text. This is due to the server listening on the network interface instead of the localhost interface.
Recommendations
For versions through 6.11, reconfigure the server to listen on the localhost interface instead of the network interface to prevent unauthorized access. Additionally, consider restricting access to the Solr service to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Docuware Fulltext Search Server
Solr