DS3 Authentication Server 'ServerAdmin/ErrorViewer.jsp' Security Bypass Vulnerability
BID:60936
Info
DS3 Authentication Server 'ServerAdmin/ErrorViewer.jsp' Security Bypass Vulnerability
| Bugtraq ID: | 60936 |
| Class: | Design Error |
| CVE: |
CVE-2013-4098 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 02 2013 12:00AM |
| Updated: | Nov 15 2013 12:44AM |
| Credit: | Pedro Andujar |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
DS3 Authentication Server 'ServerAdmin/ErrorViewer.jsp' Security Bypass Vulnerability
DS3 Authentication Server is prone to a security-bypass vulnerability.
Note: This issue was previously covered in BID 60287 (DS3 Authentication Server Security Bypass and Remote Command Execution Vulnerabilities), but has been moved to its own record for better documentation.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions.
DS3 Authentication Server is prone to a security-bypass vulnerability.
Note: This issue was previously covered in BID 60287 (DS3 Authentication Server Security Bypass and Remote Command Execution Vulnerabilities), but has been moved to its own record for better documentation.
An attacker may exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Exploit / POC
DS3 Authentication Server 'ServerAdmin/ErrorViewer.jsp' Security Bypass Vulnerability
An attacker can exploit this issue using a web browser.
The researcher who found the issue has created a proof-of-concept. Please see the references for information.
An attacker can exploit this issue using a web browser.
The researcher who found the issue has created a proof-of-concept. Please see the references for information.
Solution / Fix
DS3 Authentication Server 'ServerAdmin/ErrorViewer.jsp' Security Bypass Vulnerability
Solution:
Vendor plans to release fixes to address this issue in Q4 2014.
Solution:
Vendor plans to release fixes to address this issue in Q4 2014.
References
DS3 Authentication Server 'ServerAdmin/ErrorViewer.jsp' Security Bypass Vulnerability
References:
References: