Vulnerabilities > CVE-2018-6443 - Credentials Management vulnerability in multiple products

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
brocade
netapp
CWE-255
exploit available

Summary

A vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications. A remote unauthenticated user who has access to Network Advisor client libraries and able to decrypt the Jboss credentials could gain access to the Jboss web console.

Vulnerable Configurations

Part Description Count
Application
Brocade
2
Application
Netapp
1

Common Weakness Enumeration (CWE)

Exploit-Db

idEDB-ID:46887
last seen2019-05-21
modified2019-05-21
published2019-05-21
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46887
titleBrocade Network Advisor 14.4.1 - Unauthenticated Remote Code Execution

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/153035/brocadena1441-exec.txt
idPACKETSTORM:153035
last seen2019-05-24
published2019-05-23
reporterJakub Palaczynski
sourcehttps://packetstormsecurity.com/files/153035/Brocade-Network-Advisor-14.4.1-Unauthenticated-Remote-Code-Execution.html
titleBrocade Network Advisor 14.4.1 Unauthenticated Remote Code Execution