CVE-2020-9352

An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."
Configurations

Configuration 1 (hide)

cpe:2.3:a:smartclient:smartclient:12.0:*:*:*:*:*:*:*

History

07 Nov 2023, 15:15

Type Values Removed Values Added
References
  • () https://www-demos.smartclient.com/smartclient-12.0/isomorphic/system/reference/?id=group..toolsDeployment -
Summary An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."

18 Apr 2022, 15:58

Type Values Removed Values Added
CWE CWE-776 CWE-611
References (MISC) https://blog.certimetergroup.com/it/articolo/security/smartclient-v12-xml-external-entity--cve-2020-9352 - (MISC) https://blog.certimetergroup.com/it/articolo/security/smartclient-v12-xml-external-entity--cve-2020-9352 - Exploit, Third Party Advisory

Information

Published : 2020-02-23 02:15

Updated : 2024-04-11 01:09


NVD link : CVE-2020-9352

Mitre link : CVE-2020-9352

CVE.ORG link : CVE-2020-9352


JSON object : View

Products Affected

smartclient

  • smartclient
CWE
CWE-611

Improper Restriction of XML External Entity Reference