Overview
Telos Automated Message Handling System (AMHS) contains multiple XSS vulnerabilities and a database information disclosure vulnerability.
Description
Telos AMHS is a web-based messaging system that supports DoD and Intelligence Community (IC) security marking requirements. AMHS versions prior to version 4.1.5.5 contain multiple XSS vulnerabilities and also fail to properly restrict access to information about other users on the system. |
Impact
By creating a specially-crafted AMHS URI, an attacker may be able to inject arbitrary JavaScript into an AMHS session or access information about other AMHS users. |
Solution
Apply an update These issues are addressed in AMHS version 4.1.5.5. Please contact Telos for update availability. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.4 | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Temporal | 5 | E:POC/RL:OF/RC:C |
Environmental | 3.8 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2019-9537, CVE-2019-9538, CVE-2019-9539, CVE-2019-9540, CVE-2019-9541, CVE-2019-9542 |
Date Public: | 2019-12-19 |
Date First Published: | 2019-12-19 |
Date Last Updated: | 2019-12-19 20:39 UTC |
Document Revision: | 15 |