PT-2021-19629 · Jump Ams · Jump Ams

Thomas Pianezzola

·

Published

2021-08-03

·

Updated

2021-08-12

·

CVE-2021-32017

CVSS v3.1

9.9

Critical

VectorAC:L/AV:N/A:H/C:H/I:H/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions: JUMP AMS version 3.6.0.04.009-2487
Description: An issue was discovered in JUMP AMS where a JUMP SOAP endpoint permitted the listing of the content of the remote file system. This can be used to identify the complete server filesystem structure, including all directories and files.
Recommendations: For JUMP AMS version 3.6.0.04.009-2487, consider restricting access to the JUMP SOAP endpoint to minimize the risk of exploitation. As a temporary workaround, disabling the endpoint until a patch is available can help mitigate the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-32017

Affected Products

Jump Ams