Overview
The BES daemon in OPeNDAP server version 4 contains a vulnerability. This vulnerability may allow an attacker to execute arbitrary commands, or upload files to a remote server.
Description
OPeNDAP is a software package designed to help researchers exchange data sets that are stored in different formats. The most recent version of OPeNDAP is server 4, or Hyrax. The Hyrax server includes a daemon called BES. From the BES download page: |
Impact
An attacker to execute arbitrary commands on a vulnerable server. |
Solution
Upgrade |
Restrict access
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to NCIRT labs for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 2.42 |
Date Public: | 2007-05-14 |
Date First Published: | 2007-05-18 |
Date Last Updated: | 2007-05-21 19:04 UTC |
Document Revision: | 18 |