Vulnerabilities > CVE-2012-0147 - Configuration vulnerability in Microsoft Forefront Unified Access Gateway 2010
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
Msbulletin
bulletin_id | MS12-026 |
bulletin_url | |
date | 2012-04-12T00:00:00 |
impact | Information Disclosure |
knowledgebase_id | 2663860 |
knowledgebase_url | |
severity | Important |
title | Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Information Disclosure |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS12-026.NASL |
description | The version of Forefront Unified Access Gateway (UAG) running on the remote host has multiple vulnerabilities : - A spoofing vulnerability that could allow an attacker to redirect a victim to a malicious website. An attacker would have to trick the victim into clicking a specially crafted link in order to trigger the vulnerability. (CVE-2012-0146) - A flaw that could allow an unauthenticated user to access the default website of the UAG server from the external network. (CVE-2012-0147) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 58658 |
published | 2012-04-11 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/58658 |
title | MS12-026: Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Information Disclosure (2663860) |
code |
|
Oval
accepted | 2012-05-28T04:01:14.278-04:00 | ||||||||
class | vulnerability | ||||||||
contributors |
| ||||||||
definition_extensions |
| ||||||||
description | Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability." | ||||||||
family | windows | ||||||||
id | oval:org.mitre.oval:def:15557 | ||||||||
status | accepted | ||||||||
submitted | 2012-04-10T13:00:00 | ||||||||
title | Unfiltered Access to UAG Default Website Vulnerability | ||||||||
version | 24 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 52909 CVE ID: CVE-2012-0147 Forefront Unified Access Gateway(UAG)是一款远程访问和协作软件。 Microsoft Forefront Unified Access Gateway (UAG)中存在漏洞,未验证用户可访问UAG服务器的默认网站,获取敏感信息。 0 Microsoft Forefront UAG 2010 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS12-026)以及相应补丁: MS12-026:Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Information Disclosure (2663860) 链接:http://www.microsoft.com/technet/security/bulletin/MS12-026.asp |
id | SSV:60042 |
last seen | 2017-11-19 |
modified | 2012-04-12 |
published | 2012-04-12 |
reporter | Root |
title | Microsoft Forefront Unified Access Gateway信息泄露漏洞(MS12-026) |
References
- http://osvdb.org/81132
- http://secunia.com/advisories/48787
- http://www.securityfocus.com/bid/52909
- http://www.securitytracker.com/id?1026909
- http://www.us-cert.gov/cas/techalerts/TA12-101A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-026
- https://exchange.xforce.ibmcloud.com/vulnerabilities/74368
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15557