CVE-2017-14105

CVE-2017-14105

HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An authenticated, local attacker – even restricted as a tenant – can add a jsp at HiveManager/tomcat/webapps/hm/domains/$yourtenant/maps (it will be exposed at the web interface).

Source: CVE-2017-14105

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다