vendor:
CatDV
by:
Christopher Ellis, Nick Gonella, Workday Inc.
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: CatDV
Affected Version From: 9.2
Affected Version To: 9.2
Patch Exists: YES
Related CWE:
CPE: a:squarebox:catdv
Platforms Tested: Windows, Mac
2021
CatDV 9.2 – RMI Authentication Bypass
The exploit allows an attacker to bypass authentication in CatDV version 9.2 and lower. By manipulating the getValidSession() function, the attacker can generate a valid session and gain unauthorized access to the server. This vulnerability can be exploited remotely through the RMI protocol.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to CatDV version 9.3 or higher. Additionally, it is recommended to restrict access to the RMI service to trusted networks only.