PT-2022-12475 · Apache · Apache Tomcat

Published

2022-03-18

·

Updated

2022-07-12

·

CVE-2021-45968

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pascom Cloud Phone System versions prior to 7.20.x
Description An issue was discovered in the XMPP Server component of the JIve platform, allowing Server-Side Request Forgery (SSRF) through an endpoint in the backend Tomcat server. SSRF is a security issue where an attacker can manipulate a server into making requests to internal or external systems, potentially leading to unauthorized access or data exposure.
Recommendations For versions prior to 7.20.x, update to version 7.20.x or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable endpoint in the Tomcat server to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-45968

Affected Products

Apache Tomcat