ABB Cylon Aspect version 3.08.01 is vulnerable to remote, arbitrary servlet inclusion. The jsonProxy.php endpoint allows unauthenticated remote attackers to access internal services by proxying requests to localhost. This results in an authentication bypass, enabling attackers to interact with multiple java servlets without authorization,...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2388145
💾 ABB Cylon Aspect 3.08.01 jsonProxy.php Servlet Inclusion Authentication Bypass
⏱️ vor 635d 20h (30.10.2024 um 16:25 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com