TUCoPS :: Web :: CMS / Portals :: tb13667.htm

BEA Plumtree portal full version disclosure vulnerability
PR06-09: BEA Plumtree portal full version disclosure vulnerability
PR06-09: BEA Plumtree portal full version disclosure vulnerability



PR06-09: BEA Plumtree portal full version disclosure vulnerability=0D
=0D
Description:=0D
=0D
BEA Plumtree portal 6.0 is vulnerable to a full version disclosure vulnerability.=0D
=0D
The exact version along with the build date is always included at the bottom of every requested HTML page within HTML comments.=0D
=0D
Date Found: 12th September 2006=0D
=0D
Vendor contacted: 18th May 2007=0D
=0D
Vulnerable: BEA Plumtree 5.0.2, 5.0.3, 5.0.4, 6.0.1.218452 and possibly other versions.=0D
=0D
Severity: Low=0D
=0D
Authors: Adrian Pastor and Jan Fry of ProCheckUp Ltd (www.procheckup.com)=0D 
=0D
ProCheckUp thanks BEA for working with us.=0D
=0D
Proof of concept:=0D
=0D
The following is an example of full version information and build date disclosed within HTML comments:=0D
=0D
=0D
=0D
Consequences:=0D
=0D
Attackers can use specific version information in order to launch exploits that work on the enumerated version. This allows attackers to narrow down the number of exploits that might work  against the target.=0D
=0D
Fix:=0D
=0D
This has been addressed in AquaLogic Interaction 6.1. MP1. This can also be addressed by making config changes in ALUI 6.x versions.=0D
=0D
References:=0D
=0D
http://www.procheckup.com/Vulnerability_2007.php=0D 
http://dev2dev.bea.com/pub/advisory/252=0D 
http://www.plumtree.com/=0D 

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH