vendor:
JEUS
by:
Simon Ryeo
7.5
CVSS
HIGH
Remote File Disclosure
N/A
CWE
Product Name: JEUS
Affected Version From: < JEUS 5: Fix#26 on NTFS
Affected Version To: 5.x(each verison will be offered below Fix#26)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: NTFS
2008
TmaxSoft JEUS Alternate Data Streams Vulnerability
On NTFS TmaxSoft JEUS, which is an famous web application server, contained a vulnerability that allows an attacker to obtain web application source files. This was caused by ADSs(Alternate Data Streams; ::$DATA). JEUS couldn't handle ::$DATA. So it treated test.jsp::$DATA as an normal file when it requested. This is similar to the past MS Windows IIS vulnerability(Bid 0149). The attacker can obtain them easily using an URL request. http://www.target.com/foo/bar.jsp::$DATA
Mitigation:
The vendor released solutions for this problem. Method 1) Upgrade JEUS - JEUS 5: http://technet.tmax.co.kr/kr/download/platformList.do?groupCode=WAS&product Code=Jeus&versionCode=5.0.0.26.P&fc=down&sc=down_product&mid=binary - JEUS 4: a. Use to change WebtoB function b. Upgrade JEUS to version 6 (the service for version 4 will be out of service after Dec 2009) Method 2) Use to change WebtoB fuction - Change the message communication method from 'URI' to 'EXT' (This is valid whether you use the embed WebtoB to JEUS or the single WebtoB) Method 3) Install the patch (ex. jext.jar) - The patch file will be valid until Jan. 2009 (Target version: 3.3.7.15, 4.0, 4.1, 4.2 final, 5.x(each verison will be offered below Fix#26)