Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title BigAnt IM Message server and components contain multiple vulnerabilities
Informations
Name VU#990652 First vendor Publication 2013-01-09
Vendor VU-CERT Last vendor Modification 2013-01-09
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Vulnerability Note VU#990652

BigAnt IM Message server and components contain multiple vulnerabilities

Original Release date: 09 Jan 2013 | Last revised: 09 Jan 2013

Overview

BigAnt IM Message server and components contain multiple vulnerabilities which could allow an attacker to perform administrative functions on the the system

Description

CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') - CVE-2012-6273

During the SHU request (search user) from the bigant messaging client, a sql query is built from a template and sent via a http like header. Proper sanitization is not performed. It has been reported this can be demonstrated by opening up the BigAnt Messenger Client, logging into a server, and searching for an 'Account/Full Name' of blah' OR hs_User.Col_Pword LIKE '[a-z]

CWE-280: Improper Handling of Insufficient Permissions or Privileges - CVE-2012-6274
Arbitrary unauthenticated file upload in BigAnt IM Server. It has been reported that authentication for file uploads is not enforced. Uploaded files were reported to be saved to C:\Program Files\BigAntSoft\AntServer\DocData\Public.

CWE-121: Stack-based Buffer Overflow - CVE-2012-6275
Buffer overflow in AntDS.exe component of BigAnt Message server when handling the filename header in SCH requests and userid component of DUPF requests.

Impact

A remote unauthenticated attacker may obtain sensitive information, cause a denial of service condition or execute arbitrary code with the privileges of the application.

Solution

We are currently unaware of a practical solution to this problem.

Restrict access

As a general good security practice, only allow connections from trusted hosts and networks. Note that restricting access does not prevent SQLi, unauthenticated file uploads, or denial of service attacks since the attack comes as an HTTP request from a legitimate user's host. Restricting access would prevent an attacker from accessing a web interface using stolen credentials from a blocked network location.

Vendor Information (Learn More)

VendorStatusDate NotifiedDate Updated
BigAntSoftAffected-04 Jan 2013
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

GroupScoreVector
Base9.7AV:N/AC:L/Au:N/C:P/I:C/A:C
Temporal7.5E:POC/RL:W/RC:UC
Environmental1.9CDP:L/TD:L/CR:ND/IR:ND/AR:ND

References

  • http://cwe.mitre.org/data/definitions/89.html
  • http://cwe.mitre.org/data/definitions/280.html
  • http://cwe.mitre.org/data/definitions/121.html
  • http://www.bigantsoft.com/download.html

Credit

Thanks to hamburgers maccoy for reporting this vulnerability.

This document was written by Michael Orlando.

Other Information

  • CVE IDs:CVE-2012-6273CVE-2012-6274CVE-2012-6275
  • Date Public:09 Jan 2013
  • Date First Published:09 Jan 2013
  • Date Last Updated:09 Jan 2013
  • Document Revision:9

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.

Original Source

Url : http://www.kb.cert.org/vuls/id/990652

CWE : Common Weakness Enumeration

% Id Name
33 % CWE-287 Improper Authentication
33 % CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
33 % CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('SQL Injection') (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

SAINT Exploits

Description Link
BigAnt Messenger Server DUPF Arbitrary File Upload More info here
BigAnt Server SCH and DUPF Stack Overflow More info here

Snort® IPS/IDS

Date Description
2014-01-10 BigAnt Document Service DUPF command arbitrary file upload attempt
RuleID : 26390 - Revision : 4 - Type : SERVER-OTHER
2014-01-10 BigAnt Document Service DUPF command arbitrary file upload attempt
RuleID : 26389 - Revision : 5 - Type : SERVER-OTHER
2014-01-10 BigAnt IM Server buffer overflow attempt
RuleID : 26105 - Revision : 10 - Type : SERVER-OTHER

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2020-05-23 13:17:16
  • Multiple Updates
2013-02-25 21:19:40
  • Multiple Updates
2013-02-24 13:23:21
  • Multiple Updates
2013-01-11 21:22:31
  • Multiple Updates
2013-01-09 17:18:36
  • First insertion