MantisBT SOAP API CVE-2012-2691 Security Bypass Vulnerability
BID:56467
Info
MantisBT SOAP API CVE-2012-2691 Security Bypass Vulnerability
| Bugtraq ID: | 56467 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-2691 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2012 12:00AM |
| Updated: | Jun 14 2012 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Mantisbt Mantisbt 1.2.9 Mantisbt Mantisbt 1.2.8 Mantisbt Mantisbt 1.2.7 Mantisbt Mantisbt 1.2.6 Mantisbt Mantisbt 1.2.4 Mantisbt Mantisbt 1.2.3 Mantisbt Mantisbt 1.1 Mantisbt Mantisbt 1.2.2 Mantisbt Mantisbt 1.2.1 Gentoo Linux |
| Not Vulnerable: | |
Discussion
RETIRED: MantisBT SOAP API CVE-2012-2691 Security Bypass Vulnerability
MantisBT is prone to a security-bypass vulnerability that may allow attackers to perform actions without proper authorization.
Attackers can exploit this issue to bypass security restrictions to obtain sensitive information or perform unauthorized actions; this may aid in launching further attacks.
NOTE: This BID is being retired as a duplicate of BID 53907 (MantisBT SOAP API Security Bypass Vulnerability).
MantisBT versions prior to 1.2.11 are vulnerable.
MantisBT is prone to a security-bypass vulnerability that may allow attackers to perform actions without proper authorization.
Attackers can exploit this issue to bypass security restrictions to obtain sensitive information or perform unauthorized actions; this may aid in launching further attacks.
NOTE: This BID is being retired as a duplicate of BID 53907 (MantisBT SOAP API Security Bypass Vulnerability).
MantisBT versions prior to 1.2.11 are vulnerable.
Exploit / POC
MantisBT SOAP API CVE-2012-2691 Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
RETIRED: MantisBT SOAP API CVE-2012-2691 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RETIRED: MantisBT SOAP API CVE-2012-2691 Security Bypass Vulnerability
References:
References:
- MantisBT - Change Log Released 2012-06-06 (MantisBT)
- MantisBT 1.2.11 security update (MantisBT)
- MantisBT Homepage (MantisBT)
- MantisBT Issues Report : 0014340 (MantisBT)