An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NJivesoftware Jive
APPJivesoftwarewszystkie wersjePascom Cloud Phone System
APPPascom≤ 7.19
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
SSRF
CWE
Referencje
Powiązane podatności
CVE-2021-45966CRITICAL9.8PL ✓ten sam produkt
Command Injection w Pascom Cloud Phone System — zdalne wykonanie kodu
CVE-2021-45967CRITICAL9.8PL ✓ten sam produkt
Path traversal w Pascom Cloud Phone System przez błąd konfiguracji NGINX/Tomcat
CVE-2016-4334MEDIUM6.1ten sam produkt
Jive before 2016.3.1 has an open redirect from the external-link.jspa page.