Overview
AutoFORM PDM Archive contains multiple vulnerabilities which could allow an attacker to execute arbitrary code with the privileges of the application.
Description
According to AutoFORM's website AutoFORM PDM Archive is a comprehensive output management solution that encompasses document creation, design and electronic distribution with a fully integrated online document archiving and viewing system. AutoFORM PDM Archive software contains multiple vulnerabilities. CWE-648: Incorrect Use of Privileged APIs CVE-2012-1827: |
Impact
A remote unauthenticated attacker may obtain sensitive information, cause a denial of service condition or execute arbitrary code with the privileges of the application. |
Solution
Apply an Update
|
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6 | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Temporal | 4.7 | E:POC/RL:OF/RC:C |
Environmental | 1.6 | CDP:LM/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to David Elze of Daimler TSS GmbH for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2012-1827, CVE-2012-1828, CVE-2012-1829 |
Date Public: | 2012-05-29 |
Date First Published: | 2012-05-29 |
Date Last Updated: | 2012-05-30 13:33 UTC |
Document Revision: | 20 |