PT-2022-10270 · Idsscheer · Mashzone Nextgen

Marcos Díaz

·

Published

2022-03-30

·

Updated

2022-04-06

·

CVE-2021-33581

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MashZone NextGen versions through 10.7 GA
Description The issue allows an attacker to interact with arbitrary TCP services by abusing the feature to check the availability of a PPM connection. This occurs in the com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService class.
Recommendations For MashZone NextGen versions through 10.7 GA, consider restricting access to the com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService class until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-33581

Affected Products

Mashzone Nextgen