CVE-2019-14222 Information

Description

An issue was discovered in Alfresco Community Edition versions 6.0 and lower. An unauthenticated remote attacker could authenticate to Alfresco’s Solr Web Admin Interface. The vulnerability is due to the presence of a default private key that is present in all default installations. An attacker could exploit this vulnerability by using the extracted private key and bundling it into a PKCS12. A successful exploit could allow the attacker to gain information about the target system (e.g. OS type system file locations Java version Solr version etc.) as well as the ability to launch further attacks by leveraging the access to Alfresco’s Solr Web Admin Interface.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-14222-Default20Certificate-Alfresco20Community

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: