| Title | Apache Synapse および Commons Collections におけるインジェクションに関する脆弱性 |
|---|---|
| Summary | Apache Synapse および Commons Collections には、インジェクションに関する脆弱性が存在します。 |
| Possible impacts | 情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Dec. 10, 2017, midnight |
| Registration Date | Jan. 18, 2018, 4:01 p.m. |
| Last Update | Jan. 18, 2018, 4:01 p.m. |
| CVSS3.0 : 緊急 | |
| Score | 9.8 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVSS2.0 : 危険 | |
| Score | 7.5 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| Apache Software Foundation |
| Apache Commons Collections |
| Apache Synapse |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2018年01月18日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version. |
|---|---|
| Publication Date | Dec. 12, 2017, 12:29 a.m. |
| Registration Date | Jan. 26, 2021, 1:17 p.m. |
| Last Update | Nov. 21, 2024, 12:15 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:apache:synapse:3.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:synapse:2.1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:synapse:2.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:synapse:1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:synapse:1.1.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:synapse:1.1.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:synapse:1.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:apache:synapse:1.1:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:oracle:financial_services_market_risk_measurement_and_management:8.0.8:*:*:*:*:*:*:* | |||||