CVE-2019-14222 Information
Feb 14, 2021
cve
Description
An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated remote attacker could authenticate to Alfresco’s Solr Web Admin Interface. The vulnerability is due to the presence of a default private key that is present in all default installations. An attacker could exploit this vulnerability by using the extracted private key and bundling it into a PKCS12. A successful exploit could allow the attacker to gain information about the target system (e.g. OS type system file locations Java version Solr version etc.) as well as the ability to launch further attacks by leveraging the access to Alfresco’s Solr Web Admin Interface.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: