Serena TeamTrack Remote Authentication Bypass Vulnerability
BID:10770
Info
Serena TeamTrack Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 10770 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2004 12:00AM |
| Updated: | Jul 21 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to Beyond-Security and Noam Rathaus <[email protected]>. |
| Vulnerable: |
Serena TeamTrack 6.1.1 |
| Not Vulnerable: | |
Discussion
Serena TeamTrack Remote Authentication Bypass Vulnerability
It has been reported that Serena TeamTrack is affected by remote authentication bypass vulnerability. This issue is due to a design error that allows unauthenticated users to access sensitive scripts.
Successful exploitation of this issue will allow an attacker to gain access to sensitive information such as user names, software versions, user contact information, issues information and resolution information. This issue can also be exploited to carry out cross-site scripting attacks.
It has been reported that Serena TeamTrack is affected by remote authentication bypass vulnerability. This issue is due to a design error that allows unauthenticated users to access sensitive scripts.
Successful exploitation of this issue will allow an attacker to gain access to sensitive information such as user names, software versions, user contact information, issues information and resolution information. This issue can also be exploited to carry out cross-site scripting attacks.
Exploit / POC
Serena TeamTrack Remote Authentication Bypass Vulnerability
No exploit is required to leverage this issue. The following proof of concept has been provided:
No exploit is required to leverage this issue. The following proof of concept has been provided:
Solution / Fix
Serena TeamTrack Remote Authentication Bypass Vulnerability
Solution:
Serena Software has developed fixes to address these issues. TeamTrack customers have been advised of the potential vulnerabilities, and of the fix availability. This fix is also incorporated into the latest generally available version of TeamTrack.
Solution:
Serena Software has developed fixes to address these issues. TeamTrack customers have been advised of the potential vulnerabilities, and of the fix availability. This fix is also incorporated into the latest generally available version of TeamTrack.
References
Serena TeamTrack Remote Authentication Bypass Vulnerability
References:
References:
- Serena Software's TeamTrack Sensitive Content Disclosure (SecuriTeam.com)
- TeamTrack Home Page (Serena Software)
- Vendor Home Page (Serena Software)