PT-2019-15756 · Titanhq+1 · Webtitan+1

Published

2019-12-02

·

Updated

2019-12-06

·

CVE-2019-19015

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TitanHQ WebTitan versions prior to 5.18
Description An issue in the proxy service of TitanHQ WebTitan allows connections to the internal PostgreSQL database without password authentication, enabling an attacker to fully control the appliance database. This access can lead to further exploitation, including code execution.
Recommendations For versions prior to 5.18, update to version 5.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the proxy service to minimize the risk of exploitation.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19015

Affected Products

Postgresql
Webtitan