PT-2019-12723 · Microsoft+2 · Windows+3
Published
2019-05-21
·
Updated
2020-08-24
·
CVE-2019-12270
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OpenText Brava! Enterprise and Brava! Server versions 7.5 through 16.4
Description
The issue concerns excessive permissions configured by default on Windows for OpenText Brava! Enterprise and Brava! Server. During installation, a displaylistcache file share is created with full read and write permissions for the Everyone group at both the NTFS and Share levels. This share is used for retrieving and storing documents. However, the required share level access is only read/write by the JobProcessor service account, and at the local filesystem level, the additional required permissions are read/write from the servlet engine, such as Tomcat.
Recommendations
For versions 7.5 through 16.4, restrict the displaylistcache file share permissions to only allow read/write access for the JobProcessor service account and the servlet engine, such as Tomcat, to minimize the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opentext Brava! Enterprise
Opentext Brava! Server
Apache Tomcat
Windows