SB2017063007 - Multiple vulnerabilities in Schneider Electric U.motion Builder
Published: June 30, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 secuirty vulnerabilities.
1) SQL injection (CVE-ID: CVE-2017-7973)
The vulnerability allows a remote attacker to execute arbitrary SQL commands in database.The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can use calls to various paths in order to perform arbitrary SQL statements and execute arbitrary SQL commands.
Successful exploitation of the vulnerability may allow an attacker to gain complete control over vulnerable database.
2) Path traversal (CVE-ID: CVE-2017-7974)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.The vulnerability exists due to path traversal. A remote attacker can execute arbitrary code with privileges of the current user.
Successful exploitation of the vulnerability may result in system compromise.
3) Authentication bypass (CVE-ID: CVE-2017-9956)
The vulnerability allows a remote attacker to bypass authentication.The vulnerability exists due to hard-coded valid session. A remote attacker can use that session ID as part of the HTTP cookie of a web request and bypass authentication and gain unauthorized access to the system.
4) Authentication bypass (CVE-ID: CVE-2017-9957)
The vulnerability allows a remote attacker to bypass authentication.The vulnerability exists due to use of hard-coded password. A remote attacker can bypass authentication and gain unauthorized access to the system.
5) Arbitrary code execution (CVE-ID: CVE-2017-9958)
The vulnerability allows a local attacker to execute arbitrary code on the target system.The vulnerability exists due to improper handling of the system configuration. A local attacker can execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
6) Denial of service (CVE-ID: CVE-2017-9959)
The vulnerability allows a local attacker to cause DoS condition on the target system.The vulnerability exists due to improper access control. A local attacker can cause reboot of session.
Successful exploitation of the vulnerability results in denial of service.
7) Information disclosure (CVE-ID: CVE-2017-9960)
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.The vulnerability exists due to system returns more information than should be passed. A remote attacker can read arbitrary files on the system.
Successful exploitation of the vulnerability results in information disclosure.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.