PT-2018-4558 · Skybox · Skybox Platform

Published

2018-01-12

·

Updated

2018-01-24

·

CVE-2015-9246

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Skybox Platform versions prior to 7.5.201
Description An issue exists in the software, allowing remote unauthenticated code execution. This is achieved by sending a WAR archive containing a JSP file to the "http://skyboxview-softwareupdate/services/CollectorSoftwareUpdate" API endpoint. The JSP file can then be reached at a specific path.
Recommendations For versions prior to 7.5.201, update to version 7.5.201 or later to resolve the issue. As a temporary workaround, consider restricting access to the /skyboxview-softwareupdate/services/CollectorSoftwareUpdate API endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-9246

Affected Products

Skybox Platform