RSA NetWitness Informer Cross Site Request Forgery and Clickjacking Vulnerabilities
BID:56786
Info
RSA NetWitness Informer Cross Site Request Forgery and Clickjacking Vulnerabilities
| Bugtraq ID: | 56786 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4608 CVE-2012-4609 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2012 12:00AM |
| Updated: | Nov 30 2012 12:00AM |
| Credit: | Vendor reported these issues. |
| Vulnerable: |
EMC RSA NetWitness Informer 0 |
| Not Vulnerable: |
EMC RSA NetWitness Informer 2.0.5.6 |
Discussion
RSA NetWitness Informer Cross Site Request Forgery and Clickjacking Vulnerabilities
RSA NetWitness Informer is prone to a cross-site request forgery and a clickjacking vulnerability.
Attackers can exploit this issue by tricking a victim into visiting a malicious webpage. The page will consist of specially crafted script code designed to perform some action on the attacker's behalf and successful exploits may allow an remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
Versions prior to RSA NetWitness Informer 2.0.5.6 are vulnerable.
RSA NetWitness Informer is prone to a cross-site request forgery and a clickjacking vulnerability.
Attackers can exploit this issue by tricking a victim into visiting a malicious webpage. The page will consist of specially crafted script code designed to perform some action on the attacker's behalf and successful exploits may allow an remote attacker to perform certain administrative actions and gain unauthorized access to the affected application. Other attacks are also possible.
Versions prior to RSA NetWitness Informer 2.0.5.6 are vulnerable.
Exploit / POC
RSA NetWitness Informer Cross Site Request Forgery and Clickjacking Vulnerabilities
An attacker can use a web browser to exploit these issues. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
An attacker can use a web browser to exploit these issues. To exploit the cross-site request-forgery issue, the attacker must entice an unsuspecting victim into visiting a malicious site.
Solution / Fix
RSA NetWitness Informer Cross Site Request Forgery and Clickjacking Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
RSA NetWitness Informer Cross Site Request Forgery and Clickjacking Vulnerabilities
References:
References: