Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.807266
Category:Web application abuses
Title:Atlassian Bamboo Multiple Vulnerabilities Feb16
Summary:Atlassian Bamboo is prone to multiple vulnerabilities.
Description:Summary:
Atlassian Bamboo is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- The Ignite Realtime Smack XMPP API does not validate serialized data
in an XMPP message.

- The multiple unspecified services do not require authentication.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to execute arbitrary java code, and to obtain sensitive information,
modify settings, or manage build agents.

Affected Software/OS:
Atlassian Bamboo 2.4 through 5.9.9

Solution:
Upgrade to version 5.9.9 or later

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: BugTraq ID: 83104
BugTraq ID: 83107
Common Vulnerability Exposure (CVE) ID: CVE-2015-8361
Bugtraq: 20160122 January 2016 - Bamboo - Critical Security Advisory (Google Search)
http://www.securityfocus.com/archive/1/537347/100/0/threaded
http://packetstormsecurity.com/files/135352/Bamboo-Deserialization-Missing-Authentication-Checks.html
Common Vulnerability Exposure (CVE) ID: CVE-2014-9757
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.