search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Telos Automated Message Handling System contains multiple vulnerabilities

Vulnerability Note VU#873161

Original Release Date: 2019-12-19 | Last Revised: 2019-12-19

Overview

Telos Automated Message Handling System (AMHS) contains multiple XSS vulnerabilities and a database information disclosure vulnerability.

Description

Telos AMHS is a web-based messaging system that supports DoD and Intelligence Community (IC) security marking requirements. AMHS versions prior to version 4.1.5.5 contain multiple XSS vulnerabilities and also fail to properly restrict access to information about other users on the system.

Impact

By creating a specially-crafted AMHS URI, an attacker may be able to inject arbitrary JavaScript into an AMHS session or access information about other AMHS users.

Solution

Apply an update

These issues are addressed in AMHS version 4.1.5.5. Please contact Telos for update availability.

Vendor Information

873161
 
Affected   Unknown   Unaffected

Telos

Notified:  December 16, 2019 Updated:  December 19, 2019

Status

  Affected

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 6.4 AV:N/AC:L/Au:N/C:P/I:P/A:N
Temporal 5 E:POC/RL:OF/RC:C
Environmental 3.8 CDP:ND/TD:M/CR:ND/IR:ND/AR:ND

References

Acknowledgements

This document was written by Will Dormann.

Other Information

CVE IDs: CVE-2019-9537, CVE-2019-9538, CVE-2019-9539, CVE-2019-9540, CVE-2019-9541, CVE-2019-9542
Date Public: 2019-12-19
Date First Published: 2019-12-19
Date Last Updated: 2019-12-19 20:39 UTC
Document Revision: 14

Sponsored by the Department of Homeland Security Office of Cybersecurity and Communications.