Vulnerabilities 2007 Banner
Friday 21 November 2008

PR06-09: BEA Plumtree portal full version disclosure vulnerability

Description:

BEA Plumtree portal 6.0 is vulnerable to a full version disclosure vulnerability.

The exact version along with the build date is always included at the bottom of
every requested HTML page within HTML comments.

Date Found: 12th September 2006

Vendor contacted: 18th May 2007

Vulnerable: BEA Plumtree 5.0.2, 5.0.3, 5.0.4, 6.0.1.218452 and possibly other versions.

Severity: Low

CVE reference: CVE-2007-6197

Authors: Adrian Pastor [adrian.pastor [at] procheckup.com] and Jan Fry [jan.fry [at] procheckup.com] from ProCheckUp Ltd (www.procheckup.com)

ProCheckUp thanks BEA for working with us.

Proof of concept:

The following is an example of full version information and build date disclosed
within HTML comments:

<!--Portal Version: 6.0.1.218452, Changelist: 218452, Build Date: 04/07/2006 at 10:13 AM-->

Consequences:

Attackers can use specific version information in order to lauch exploits that work on the enumerated version. This allows attackers to narrow down the number of exploits that might work against the target.

This has been addressed in AquaLogic Interaction 6.1. MP1. This can also be addressed by making config changes in ALUI 6.x versions.

References:

http://www.plumtree.com/
http://dev2dev.bea.com/pub/advisory/252
http://www.procheckup.com/Vulnerability_2007.php

Legal:

Copyright 2007 ProCheckUp Ltd.

All rights reserved. Permission is granted for copying and circulating this Bulletin to the Internet community for the purpose of alerting them to problems, if and only if the Bulletin is not changed or edited in any way, is attributed to ProCheckUp indicating this web page URL, and provided such reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited.

ProCheckUp is not liable for any misuse of this information by any third party. ProCheckUp is not responsible for the content of external Internet sites.

Case Study SC Magazine
Sample Report
Press Releases
 
  Site Map
Privacy Policy
Terms and Conditions
© ProCheckUp Ltd 2008