PT-2019-13544 · Alfresco · Alfresco Community Edition
Published
2019-09-05
·
Updated
2020-08-24
·
CVE-2019-14224
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Alfresco Community Edition version 5.2 201707
Description
An issue was discovered that allows an attacker to achieve remote code execution on the victim machine by leveraging multiple components in the Alfresco Software applications. The attacker must upload malicious Solr configuration files and then receive a JMX connection from the victim, and serve a Java object that results in deserialization and code execution.
Recommendations
For Alfresco Community Edition version 5.2 201707, consider restricting access to the Solr configuration files and limiting JMX connections to trusted sources until a patch is available. As a temporary workaround, consider disabling the ability to upload Solr configuration files to minimize the risk of exploitation.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alfresco Community Edition