An issue was discovered in xmppserver jar in the XMPP Server component of the JIve platform, as used in Pascom Cloud Phone System before 7.20.x (and in other products). An endpoint in the backend Tomcat server of the Pascom allows SSRF, a related issue to CVE-2019-18394.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NJivesoftware Jive
APPJivesoftwareall versionsPascom Cloud Phone System
APPPascom≤ 7.19
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRF
CWE
References
Related vulnerabilities
CVE-2021-45966CRITICAL9.8PL ✓same product
Command Injection w Pascom Cloud Phone System — zdalne wykonanie kodu
CVE-2021-45967CRITICAL9.8PL ✓same product
Path traversal w Pascom Cloud Phone System przez błąd konfiguracji NGINX/Tomcat
CVE-2016-4334MEDIUM6.1same product
Jive before 2016.3.1 has an open redirect from the external-link.jspa page.