Zenoss CVE-2014-6256 Authorization Bypass Vulnerability
BID:71526
Info
Zenoss CVE-2014-6256 Authorization Bypass Vulnerability
| Bugtraq ID: | 71526 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-6256 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 05 2014 12:00AM |
| Updated: | Dec 05 2014 12:00AM |
| Credit: | Ryan Koppenhaver and Andy Schmitz of Matasano Security. |
| Vulnerable: |
Zenoss Zenoss Core 4.2.4 |
| Not Vulnerable: | |
Discussion
Zenoss CVE-2014-6256 Authorization Bypass Vulnerability
Zenoss is prone to an authorization-bypass vulnerability because of insufficient authorization enforcement.
Attackers can exploit this issue to obtain sensitive information that may aid in further attacks.
Zenoss 4.2.4 is vulnerable.
Zenoss is prone to an authorization-bypass vulnerability because of insufficient authorization enforcement.
Attackers can exploit this issue to obtain sensitive information that may aid in further attacks.
Zenoss 4.2.4 is vulnerable.
Exploit / POC
Zenoss CVE-2014-6256 Authorization Bypass Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Zenoss CVE-2014-6256 Authorization Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Zenoss CVE-2014-6256 Authorization Bypass Vulnerability
References:
References: