Vignette Content Management Unspecified Security Bypass Vulnerability
BID:31328
Info
Vignette Content Management Unspecified Security Bypass Vulnerability
| Bugtraq ID: | 31328 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-6412 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 23 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | National Australia Bank's Security Assurance Team |
| Vulnerable: |
Vignette Vignette Content Management 7.3.1 Vignette Vignette Content Management 7.5 Vignette Vignette Content Management 7.4 Vignette Vignette Content Management 7.3.1.1 Vignette Vignette Content Management 7.3.0.5 |
| Not Vulnerable: | |
Discussion
Vignette Content Management Unspecified Security Bypass Vulnerability
Vignette Content Management (VCM) is prone to a security-bypass vulnerability because of an unspecified error.
Successfully exploiting this issue allows remote attackers to gain administrative privileges to the affected application. This may allow attackers to create, approve, and publish content as well as change application configurations.
This issue affects VCM 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 as well as all associated service packs.
Vignette Content Management (VCM) is prone to a security-bypass vulnerability because of an unspecified error.
Successfully exploiting this issue allows remote attackers to gain administrative privileges to the affected application. This may allow attackers to create, approve, and publish content as well as change application configurations.
This issue affects VCM 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 as well as all associated service packs.
Exploit / POC
Vignette Content Management Unspecified Security Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Vignette Content Management Unspecified Security Bypass Vulnerability
Solution:
The vendor has released fixes to address the issue for VCM 7.3.1 to 7.5. The vendor is currently working on a fix for VCM 7.3.0.5. Please see the references for more information.
Solution:
The vendor has released fixes to address the issue for VCM 7.3.1 to 7.5. The vendor is currently working on a fix for VCM 7.3.0.5. Please see the references for more information.
References
Vignette Content Management Unspecified Security Bypass Vulnerability
References:
References:
- Vignette Content Management Security Update (Vignette)
- Vignette Homepage (VIGNETTE)