VULNERABILITIES / FIXES - December 04, 2012
by Carol~
- 12/4/12 11:36 PM
RSA NetWitness Informer Clickjacking and Cross-Site Request Forgery Vulnerabilities
Release Date: 2012-12-04
Criticality level : Less critical
Impact Cross Site Scripting
Where : From remote
Solution Status : Vendor Patch
Software: NetWitness Informer 2.x
Description:
Two vulnerabilities have been reported in RSA NetWitness Informer, which can be exploited by malicious people to conduct click-jacking and cross-site request forgery attacks.
1) The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain unspecified actions if a logged-in user visits a malicious web site.
2) The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain unspecified actions by tricking a user into clicking a specially crafted link via clickjacking.
The vulnerabilities are reported in versions prior to 2.0.5.6.
Solution:
Update to version 2.0.5.6.
Provided and/or discovered by:
Reported by the vendor.
Original Advisory:
EMC:
http://archives.neohapsis.com/archives/bugtraq/2012-12/att-0002/ESA-2012-052.txt
http://secunia.com/advisories/51483/

Moderator
CNET Staff
Samsung Staff
Dell Staff