CVE-2019-12270
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displaylistcache file share is created on the Windows server with full read and write permissions for the Everyone group at both the NTFS and Share levels. The share is used to retrieve documents for processing, and to store processed documents for display in the browser. The only required share level access is read/write by the JobProcessor service account. At the local filesystem level, the only additional required permissions would be read/write from the servlet engine, such as Tomcat. (The affected server components are not installed with Content Server by default, and must be installed separately.) NOTE: the vendor's position is that customers are not supposed to use this default setting without consulting the documentation.
OpenText Brava! Enterprise and Brava! Server 7.5 hasta 16.4 configura permisos excesivos por defecto en Windows. Durante la instalación, un recurso compartido de archivos displaylistcache es creado en el servidor de Windows con permisos completos de lectura y escritura para el grupo Everyone, tanto en los niveles NTFS como Share. La partición se usa para recuperar documentos para su procesamiento y para almacenar documentos procesados ??para visualizarlos en el navegador. El único acceso de nivel compartido requerido es de lectura /escritura por la cuenta de servicio JobProcessor. En el nivel local filesystem, los únicos permisos adicionales necesarios serían los de lectura /escritura desde el motor servlet, como Tomcat. (Los componentes del servidor afectados no se instalan con Content Server por defecto y deben instalarse separadamente). NOTA: la posición del proveedor es que los clientes no deben usar esta configuración predeterminada sin consultar la documentación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-21 CVE Reserved
- 2019-05-21 CVE Published
- 2024-08-04 CVE Updated
- 2024-10-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://packetstormsecurity.com/files/150125/Brava-Enterprise-Server-16.4-Information-Disclosure.html | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opentext Search vendor "Opentext" | Brava\! Search vendor "Opentext" for product "Brava\!" | >= 7.5 <= 16.4 Search vendor "Opentext" for product "Brava\!" and version " >= 7.5 <= 16.4" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|