PT-2018-4020 · Apache · Apache Juddi
Marc Schoenefeld
·
Published
2018-02-19
·
Updated
2018-03-18
·
CVE-2009-4267
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apache jUDDI version 3.0.0
Description
The issue concerns the console in Apache jUDDI, which fails to properly escape line feeds. This allows remote authenticated users to spoof log entries by manipulating the
numRows parameter.Recommendations
For Apache jUDDI version 3.0.0, consider restricting access to the console until a proper fix is available, and avoid using the
numRows parameter in a way that could facilitate log entry spoofing. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Juddi