PT-2019-13544 · Alfresco · Alfresco Community Edition

Published

2019-09-05

·

Updated

2020-08-24

·

CVE-2019-14224

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Alfresco Community Edition version 5.2 201707
Description An issue was discovered that allows an attacker to achieve remote code execution on the victim machine by leveraging multiple components in the Alfresco Software applications. The attacker must upload malicious Solr configuration files and then receive a JMX connection from the victim, and serve a Java object that results in deserialization and code execution.
Recommendations For Alfresco Community Edition version 5.2 201707, consider restricting access to the Solr configuration files and limiting JMX connections to trusted sources until a patch is available. As a temporary workaround, consider disabling the ability to upload Solr configuration files to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14224

Affected Products

Alfresco Community Edition