ScrumWorks Pro CVE-2012-2603 Remote Privilege Escalation Vulnerability
BID:53857
Info
ScrumWorks Pro CVE-2012-2603 Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 53857 |
| Class: | Design Error |
| CVE: |
CVE-2012-2603 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2012 12:00AM |
| Updated: | Jun 07 2012 12:00AM |
| Credit: | Wolfgang Holoch and David Elze of Daimler TSS GmbH |
| Vulnerable: |
Collabnet ScrumWorks Pro 5.0 |
| Not Vulnerable: |
Collabnet ScrumWorks Pro 6.0 |
Discussion
ScrumWorks Pro CVE-2012-2603 Remote Privilege Escalation Vulnerability
ScrumWorks Pro is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges within the application and obtain unauthorized access to the sensitive information.
ScrumWorks Pro is prone to a remote privilege-escalation vulnerability.
An attacker can exploit this issue to gain elevated privileges within the application and obtain unauthorized access to the sensitive information.
Exploit / POC
ScrumWorks Pro CVE-2012-2603 Remote Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
ScrumWorks Pro CVE-2012-2603 Remote Privilege Escalation Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
ScrumWorks Pro CVE-2012-2603 Remote Privilege Escalation Vulnerability
References:
References:
- ScrumWorks Pro Homepage (Collabnet)
- ScrumWorks Pro privilege escalation vulnerability (US-CERT)