DataWatch Monarch Business Intelligence Multiple Input Validation Vulnerabilities
BID:54733
Info
DataWatch Monarch Business Intelligence Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 54733 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2012 12:00AM |
| Updated: | Jul 31 2012 12:00AM |
| Credit: | Raymond Rizk |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
DataWatch Monarch Business Intelligence Multiple Input Validation Vulnerabilities
DataWatch Monarch Business Intelligence is prone to multiple input validation vulnerabilities.
Successful exploits will allow an attacker to manipulate the XPath query logic to carry out unauthorized actions on the XML documents of the application. It will also allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
DataWatch Monarch Business Intelligence 5.1 is vulnerable; other versions may also be affected.
DataWatch Monarch Business Intelligence is prone to multiple input validation vulnerabilities.
Successful exploits will allow an attacker to manipulate the XPath query logic to carry out unauthorized actions on the XML documents of the application. It will also allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
DataWatch Monarch Business Intelligence 5.1 is vulnerable; other versions may also be affected.
Exploit / POC
DataWatch Monarch Business Intelligence Multiple Input Validation Vulnerabilities
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/ESAdmin/jsp/tabview.jsp?mode=add</script><script>alert(1)</script>&type=2&renew=1&pageid=PAGE_MPROCESS
http://www.example.com/ESClient/jsp/customizedialog.jsp?templateType=-1&doctypeid=122&activetab=DM_DOCUMENT_LIST&fields=filter;sort;summary;&searchtype=document'&doclist.jsp
Attackers can use a browser to exploit these issues. To exploit a cross-site scripting vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/ESAdmin/jsp/tabview.jsp?mode=add</script><script>alert(1)</script>&type=2&renew=1&pageid=PAGE_MPROCESS
http://www.example.com/ESClient/jsp/customizedialog.jsp?templateType=-1&doctypeid=122&activetab=DM_DOCUMENT_LIST&fields=filter;sort;summary;&searchtype=document'&doclist.jsp
Solution / Fix
DataWatch Monarch Business Intelligence Multiple Input Validation Vulnerabilities
Solution:
Reportedly, the issue is fixed. However, Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly, the issue is fixed. However, Symantec has not confirmed this. Please contact the vendor for more information.
References
DataWatch Monarch Business Intelligence Multiple Input Validation Vulnerabilities
References:
References: