Summary
This host is running F-Secure Policy Manager and is prone to cross site scripting and path disclosure vulnerabilities.
Impact
Successful exploitation will allow attacker to disclose potentially sensitive information and execute arbitrary code in the context of an application.
Impact Level: Application
Solution
F-Secure Policy Manager for Windows version 8.00 - Apply patch:
ftp://ftp.f-secure.com/support/hotfix/fspm/fspm-8.00-windows-hotfix-2.zip
F-Secure Policy Manager for Windows version 8.1x - Apply patch:
ftp://ftp.f-secure.com/support/hotfix/fspm/fspm-8.1x-windows-hotfix-3.zip
F-Secure Policy Manager for Windows version 9.00 - Apply patch:
ftp://ftp.f-secure.com/support/hotfix/fspm/fspm-9.00-windows-hotfix-4.zip
F-Secure Policy Manager for Linux version 8.00 - Apply patch:
ftp://ftp.f-secure.com/support/hotfix/fspm-linux/fspm-8.00-linux-hotfix-2.zip
F-Secure Policy Manager for Linux version 8.1x - Apply patch:
ftp://ftp.f-secure.com/support/hotfix/fspm-linux/fspm-8.1x-linux-hotfix-2.zip
F-Secure Policy Manager for Linux version 9.00 - Apply patch:
ftp://ftp.f-secure.com/support/hotfix/fspm-linux/fspm-9.00-linux-hotfix-2.zip
Insight
The flaws are caused by an error in the 'WebReporting' interface when processing user-supplied requests, which could allow cross-site scripting and path disclosure attacks.
Affected
F-Secure Policy Manager versions 7.x, 8.x and 9.x
References
Severity
Classification
-
CVE CVE-2011-1102, CVE-2011-1103 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities