Release date:
Updated on:
Affected Systems:
SpagoBI 4.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65925
CVE (CAN) ID: CVE-2013-6231
SpagoBI is an open-source business intelligence software package.
SpagoBI 4.0 and other versions of the service program AdapterHTTP? ACTION_NAME = MANAGE_USER_ACTION the privilege escalation vulnerability is triggered when specially crafted input is executed. This vulnerability allows remote attackers to gain administrator privileges.
<* Source: Christian Catalano
Link: http://www.securityfocus.com/archive/1/531318
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SpagoBI
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.spagworld.org
Http://forge.ow2.org/project/showfiles.php? Group_id = 204