CVE Vulnerabilities

CVE-2007-2975

Published: Jun 01, 2007 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allows remote attackers to gain privileges and execute arbitrary code by accessing functionality that is exposed through DWR, as demonstrated using the downloader.

Affected Software

Name Vendor Start Version End Version
Openfire Ignite_realtime * 3.3.0 (including)
Openfire Ignite_realtime 2.6.0 (including) 2.6.0 (including)
Openfire Ignite_realtime 2.6.1 (including) 2.6.1 (including)
Openfire Ignite_realtime 2.6.2 (including) 2.6.2 (including)
Openfire Ignite_realtime 3.0.0 (including) 3.0.0 (including)
Openfire Ignite_realtime 3.0.1 (including) 3.0.1 (including)
Openfire Ignite_realtime 3.1.0 (including) 3.1.0 (including)
Openfire Ignite_realtime 3.1.1 (including) 3.1.1 (including)
Openfire Ignite_realtime 3.2.0 (including) 3.2.0 (including)
Openfire Ignite_realtime 3.2.1 (including) 3.2.1 (including)
Openfire Ignite_realtime 3.2.2 (including) 3.2.2 (including)
Openfire Ignite_realtime 3.2.3 (including) 3.2.3 (including)
Openfire Ignite_realtime 3.2.4 (including) 3.2.4 (including)

References