WebDefend Enterprise Manager Appliance Hard Coded Authentication Security Bypass Vulnerability
BID:48002
Info
WebDefend Enterprise Manager Appliance Hard Coded Authentication Security Bypass Vulnerability
| Bugtraq ID: | 48002 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 26 2011 12:00AM |
| Updated: | May 26 2011 12:00AM |
| Credit: | Nathan Power |
| Vulnerable: |
Trustwave WebDefend Enterprise Manager Appliance 5.0 (7.01.903 Trustwave WebDefend Enterprise Manager Appliance 4.0 (6.45.659) |
| Not Vulnerable: | |
Discussion
WebDefend Enterprise Manager Appliance Hard Coded Authentication Security Bypass Vulnerability
WebDefend Enterprise Manager Appliance is prone to a security-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected appliance.
The following products are affected:
WebDefend Enterprise Manager Appliance / Console software 5.0 (7.01.903)
WebDefend Enterprise Manager Appliance / Console software 4.0 (6.45.659)
WebDefend Enterprise Manager Appliance is prone to a security-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected appliance.
The following products are affected:
WebDefend Enterprise Manager Appliance / Console software 5.0 (7.01.903)
WebDefend Enterprise Manager Appliance / Console software 4.0 (6.45.659)
Exploit / POC
WebDefend Enterprise Manager Appliance Hard Coded Authentication Security Bypass Vulnerability
Attackers can exploit this issue using readily available utilities.
Attackers can exploit this issue using readily available utilities.
Solution / Fix
WebDefend Enterprise Manager Appliance Hard Coded Authentication Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WebDefend Enterprise Manager Appliance Hard Coded Authentication Security Bypass Vulnerability
References:
References:
- Trustwave WebDefend Homepage (Trustwave)
- Trustwave WebDefend Static Databse Password Vulnerability (Trustwave)