PT-2017-14474 · Netgain Systems · Netgain Systems Enterprise Manager

Rgod

·

Published

2017-12-13

·

Updated

2019-10-09

·

CVE-2017-16590

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetGain Systems Enterprise Manager version 7.2.699 build 1001
Description This issue allows remote attackers to bypass authentication on vulnerable installations. User interaction is required to exploit this issue. The specific flaw exists within the MainFilter servlet, resulting from the lack of proper string matching inside the doFilter method. An attacker can leverage this in conjunction with other issues to execute arbitrary code in the context of Administrator.
Recommendations For NetGain Systems Enterprise Manager version 7.2.699 build 1001, consider disabling the doFilter method within the MainFilter servlet as a temporary workaround until a patch is available. Restrict access to the MainFilter servlet to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16590
ZDI-17-955

Affected Products

Netgain Systems Enterprise Manager