PT-2017-13831 · Docuware+1 · Docuware Fulltext Search Server+1

Published

2017-11-21

·

Updated

2019-10-03

·

CVE-2017-15044

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DocuWare Fulltext Search server versions through 6.11
Description The default installation of the server allows remote users to connect to and download searchable text from the embedded Solr service, bypassing access control features. An attacker can also gain privileges by modifying text. This is due to the server listening on the network interface instead of the localhost interface.
Recommendations For versions through 6.11, reconfigure the server to listen on the localhost interface instead of the network interface to prevent unauthorized access. Additionally, consider restricting access to the Solr service to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-15044

Affected Products

Docuware Fulltext Search Server
Solr