CVE Vulnerabilities

CVE-2007-2975

Published: Jun 01, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allows remote attackers to gain privileges and execute arbitrary code by accessing functionality that is exposed through DWR, as demonstrated using the downloader.

Affected Software

NameVendorStart VersionEnd Version
OpenfireIgnite_realtime*3.3.0 (including)
OpenfireIgnite_realtime2.6.0 (including)2.6.0 (including)
OpenfireIgnite_realtime2.6.1 (including)2.6.1 (including)
OpenfireIgnite_realtime2.6.2 (including)2.6.2 (including)
OpenfireIgnite_realtime3.0.0 (including)3.0.0 (including)
OpenfireIgnite_realtime3.0.1 (including)3.0.1 (including)
OpenfireIgnite_realtime3.1.0 (including)3.1.0 (including)
OpenfireIgnite_realtime3.1.1 (including)3.1.1 (including)
OpenfireIgnite_realtime3.2.0 (including)3.2.0 (including)
OpenfireIgnite_realtime3.2.1 (including)3.2.1 (including)
OpenfireIgnite_realtime3.2.2 (including)3.2.2 (including)
OpenfireIgnite_realtime3.2.3 (including)3.2.3 (including)
OpenfireIgnite_realtime3.2.4 (including)3.2.4 (including)

References