PT-2022-12475 · Apache · Apache Tomcat
Published
2022-03-18
·
Updated
2022-07-12
·
CVE-2021-45968
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pascom Cloud Phone System versions prior to 7.20.x
Description
An issue was discovered in the XMPP Server component of the JIve platform, allowing Server-Side Request Forgery (SSRF) through an endpoint in the backend Tomcat server. SSRF is a security issue where an attacker can manipulate a server into making requests to internal or external systems, potentially leading to unauthorized access or data exposure.
Recommendations
For versions prior to 7.20.x, update to version 7.20.x or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable endpoint in the Tomcat server to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Tomcat