Overview
Caucho's Quercus on Resin contains multiple vulnerabilities which could allow an attacker to execute arbitrary code with the privileges of the application.
Description
It has been reported that Caucho's Quercus on Resin contains multiple vulnerabilities which could allow an attacker to execute arbitrary code with the privileges of the application.
|
Impact
A remote unauthenticated attacker may obtain sensitive information, cause a denial of service condition or execute arbitrary code with the privileges of the application. |
Solution
Update |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Temporal | 5 | E:U/RL:OF/RC:UC |
Environmental | 1.4 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Sergey Scherbel for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2012-2965, CVE-2012-2966, CVE-2012-2967, CVE-2012-2968, CVE-2012-2969 |
Date Public: | 2012-07-13 |
Date First Published: | 2012-07-23 |
Date Last Updated: | 2012-07-23 19:28 UTC |
Document Revision: | 15 |