Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability
BID:6704
Info
Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability
| Bugtraq ID: | 6704 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2003 12:00AM |
| Updated: | Jan 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Compass Security. |
| Vulnerable: |
Finjan Software SurfinGate 7.0 Finjan Software SurfinGate 6.0 5 Finjan Software SurfinGate 6.0 1 Finjan Software SurfinGate 6.0 Finjan Software SurfinGate 5.6 |
| Not Vulnerable: | |
Discussion
Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability
The Finjan SurfinGate Java applet analyzer does not properly detect the use of the Java Reflection API. As a result, this API may be used to call methods and classes that may otherwise be restricted.
A malicious Java applet may use this technique to bypass the Finjan SurfinGate filter. End users may not be protected from malicious Java applets as a result.
It should be noted that this issue exists when the "Load Other Java Classes" feature is enabled (which it is by default). Disabling this feature will mitigate this issue by may cause Java applets to be blocked too aggressively. Even with this feature enabled, loaded Java classes will be scanned, which may block some malicious behavior.
The Finjan SurfinGate Java applet analyzer does not properly detect the use of the Java Reflection API. As a result, this API may be used to call methods and classes that may otherwise be restricted.
A malicious Java applet may use this technique to bypass the Finjan SurfinGate filter. End users may not be protected from malicious Java applets as a result.
It should be noted that this issue exists when the "Load Other Java Classes" feature is enabled (which it is by default). Disabling this feature will mitigate this issue by may cause Java applets to be blocked too aggressively. Even with this feature enabled, loaded Java classes will be scanned, which may block some malicious behavior.
Exploit / POC
Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability
Solution:
The vendor has announced this issue and announced that it will be addressed more completely in a future release of SurfinGate.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor has announced this issue and announced that it will be addressed more completely in a future release of SurfinGate.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Finjan SurfinGate Java Applet Analyzer Bypass Vulnerability
References:
References:
- SurfinGate Product Page (Finjan Software)
- RE: Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate V5.6 ("Menashe Eliezer"
) - Tech Article: HTTP Content Filter Analysis - Finjan SurfinGate v5.6 ("[email protected]"
)