PT-2019-12723 · Microsoft+2 · Windows+3

Published

2019-05-21

·

Updated

2020-08-24

·

CVE-2019-12270

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenText Brava! Enterprise and Brava! Server versions 7.5 through 16.4
Description The issue concerns excessive permissions configured by default on Windows for OpenText Brava! Enterprise and Brava! Server. During installation, a displaylistcache file share is created with full read and write permissions for the Everyone group at both the NTFS and Share levels. This share is used for retrieving and storing documents. However, the required share level access is only read/write by the JobProcessor service account, and at the local filesystem level, the additional required permissions are read/write from the servlet engine, such as Tomcat.
Recommendations For versions 7.5 through 16.4, restrict the displaylistcache file share permissions to only allow read/write access for the JobProcessor service account and the servlet engine, such as Tomcat, to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12270

Affected Products

Opentext Brava! Enterprise
Opentext Brava! Server
Apache Tomcat
Windows