Sun Java IDE Webserver IP Restriction Failure Vulnerability
BID:816
Info
Sun Java IDE Webserver IP Restriction Failure Vulnerability
| Bugtraq ID: | 816 |
| Class: | Access Validation Error |
| CVE: |
CVE-1999-1527 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Posted to bugtraq on November 23, 1999 by Halcyon Skinner <[email protected]>. |
| Vulnerable: |
Sun Netbeans Developer 3.0 Beta For NT Sun Forte Community Edition 1.0 Beta For NT |
| Not Vulnerable: | |
Discussion
Sun Java IDE Webserver IP Restriction Failure Vulnerability
These Java development applications include an http server for testing purposes. The server can be configured to only respond to requests from certain IP addresses, however the mechanism fails and any requests received are serviced. The server will allow read access to any file on the filesystem that it haas access to, all the way up to the root directory. In the Netbeans product, this is the default 'out of the box' configuration. In the Forte product. IP addresses must be added manually to a list of permitted clients. Once a single IP address is added, any requests regardless of source are responded to.
These Java development applications include an http server for testing purposes. The server can be configured to only respond to requests from certain IP addresses, however the mechanism fails and any requests received are serviced. The server will allow read access to any file on the filesystem that it haas access to, all the way up to the root directory. In the Netbeans product, this is the default 'out of the box' configuration. In the Forte product. IP addresses must be added manually to a list of permitted clients. Once a single IP address is added, any requests regardless of source are responded to.
Exploit / POC
Sun Java IDE Webserver IP Restriction Failure Vulnerability
http ://victim.com:8082/
http ://victim.com:8082/
Solution / Fix
Sun Java IDE Webserver IP Restriction Failure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Sun Java IDE Webserver IP Restriction Failure Vulnerability
References:
References: