Overview
GroundWork Monitor Enterprise 6.7.0 and possibly earlier versions contain multiple vulnerabilities.
Description
The SEC Consult Vulnerability Lab Security Advisory states: The following vulnerability description has been categorized into the components where the vulnerabilities have been identified. |
Impact
A remote unauthenticated attacker may be able to modify the administrator web interface of the system, read sensitive configuration files, or execute arbitrary operating system commands with the permission's of the GroundWork Monitor Enterprise system. |
Solution
Change configuration |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9 | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Temporal | 7.3 | E:POC/RL:U/RC:UC |
Environmental | 1.9 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130308-0_GroundWork_Monitoring_Multiple_critical_vulnerabilities_wo_poc_v10.txt
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20130308-1_GroundWork_Monitoring_Multiple_high_risk_vulnerabilities_part2_wo_poc_v10.txt
- https://www.sec-consult.com/en/Vulnerability-Lab/Advisories.htm
- https://kb.groundworkopensource.com/display/SUPPORT/SA6.7.0-1+Some+web+components+allow+bypass+of+role+access+controls
Acknowledgements
Thanks to Johannes Greil of SEC Consult Unternehmensberatung GmbH for reporting these vulnerabilities. https://www.sec-consult.com
This document was written by Michael Orlando.
Other Information
CVE IDs: | None |
Date Public: | 2013-03-07 |
Date First Published: | 2013-03-08 |
Date Last Updated: | 2013-03-08 19:46 UTC |
Document Revision: | 24 |