vendor:
Objectivity/DB
by:
Jeremy Brown
7.5
CVSS
HIGH
Lack of Authentication
287
CWE
Product Name: Objectivity/DB
Affected Version From: Objectivity/DB 10
Affected Version To: Objectivity/DB 10
Patch Exists: NO
Related CWE: N/A
CPE: a:objectivity:objectivity/db:10
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2011
Objectivity/DB Lack of Authentication Remote Exploit
Objectivity/DB includes many different tools for administration. The problem is, anyone can use these tools to perform operations on the host running the lock server, advanced multithreaded server, and probably it's other servers as well, without any authentication. This design flaw puts the host running these servers at risk of potentially unauthorized operations being performed on the system, locally or remotely.
Mitigation:
US-CERT coordinated the communication and released a vulnerability note after the vendor did not provide additional feedback.