Cisco Application Control Engine (ACE) XML Gateway IP Address Information Disclosure Vulnerability
BID:36522
Info
Cisco Application Control Engine (ACE) XML Gateway IP Address Information Disclosure Vulnerability
| Bugtraq ID: | 36522 |
| Class: | Design Error |
| CVE: |
CVE-2009-3457 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | Alejandro Hernandez H. |
| Vulnerable: |
Cisco Application Control Engine (ACE) XML Gateway 6.0 Cisco Application Control Engine (ACE) Web App. Firewall 6.0 Cisco ACE XML Gateway 0 |
| Not Vulnerable: |
Cisco Application Control Engine (ACE) XML Gateway 6.1 Cisco Application Control Engine (ACE) Web App. Firewall 6.1 |
Discussion
Cisco Application Control Engine (ACE) XML Gateway IP Address Information Disclosure Vulnerability
Cisco Application Control Engine (ACE) XML Gateway is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that can aid in further attacks.
This issue is being tracked by Cisco Bug CSCtb82159.
Versions prior to ACE XML Gateway 6.1 and ACE Web Application Firewall 6.1 are vulnerable.
Cisco Application Control Engine (ACE) XML Gateway is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that can aid in further attacks.
This issue is being tracked by Cisco Bug CSCtb82159.
Versions prior to ACE XML Gateway 6.1 and ACE Web Application Firewall 6.1 are vulnerable.
Exploit / POC
Cisco Application Control Engine (ACE) XML Gateway IP Address Information Disclosure Vulnerability
An attacker can use readily available utilities to exploit this issue.
The following exploit code is available:
An attacker can use readily available utilities to exploit this issue.
The following exploit code is available:
Solution / Fix
Cisco Application Control Engine (ACE) XML Gateway IP Address Information Disclosure Vulnerability
Solution:
The vendor indicates that this issue will be resolved in version 6.1, expected to be available in November 2009.
Solution:
The vendor indicates that this issue will be resolved in version 6.1, expected to be available in November 2009.
References
Cisco Application Control Engine (ACE) XML Gateway IP Address Information Disclosure Vulnerability
References:
References:
- Cisco ACE XML Gateway <= 6.0 Internal IP Address Disclosure (nitr�?us [ Alejandro Hernandez H. ])
- Cisco ACE XML Gateway Homepage (Cisco)
- Cisco ACE XML Gateway <= 6.0 Internal IP disclosure (nitr�?us
) - Cisco Security Response: Unmatched Request Discloses Client Internal IP Address (Cisco)