// For flags

CVE-2019-12270

 

Severity Score

7.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displaylistcache file share is created on the Windows server with full read and write permissions for the Everyone group at both the NTFS and Share levels. The share is used to retrieve documents for processing, and to store processed documents for display in the browser. The only required share level access is read/write by the JobProcessor service account. At the local filesystem level, the only additional required permissions would be read/write from the servlet engine, such as Tomcat. (The affected server components are not installed with Content Server by default, and must be installed separately.) NOTE: the vendor's position is that customers are not supposed to use this default setting without consulting the documentation.

OpenText Brava! Enterprise and Brava! Server 7.5 hasta 16.4 configura permisos excesivos por defecto en Windows. Durante la instalación, un recurso compartido de archivos displaylistcache es creado en el servidor de Windows con permisos completos de lectura y escritura para el grupo Everyone, tanto en los niveles NTFS como Share. La partición se usa para recuperar documentos para su procesamiento y para almacenar documentos procesados ??para visualizarlos en el navegador. El único acceso de nivel compartido requerido es de lectura /escritura por la cuenta de servicio JobProcessor. En el nivel local filesystem, los únicos permisos adicionales necesarios serían los de lectura /escritura desde el motor servlet, como Tomcat. (Los componentes del servidor afectados no se instalan con Content Server por defecto y deben instalarse separadamente). NOTA: la posición del proveedor es que los clientes no deben usar esta configuración predeterminada sin consultar la documentación.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-05-21 CVE Reserved
  • 2019-05-21 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-10-11 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Opentext
Search vendor "Opentext"
Brava\!
Search vendor "Opentext" for product "Brava\!"
>= 7.5 <= 16.4
Search vendor "Opentext" for product "Brava\!" and version " >= 7.5 <= 16.4"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe