The CollabNet Subversion Edge Management stores passwords as unsalted MD5 hashes. Unsalted MD5 hashes can easily be cracked by brute forcing the password. Fixed in version 5.0. Version 4.0.11 is affected.
Monthly Archives: June 2015
NetIQ Access Manager 4.0 SP1 XXE Injection
NetIQ Access Manager is vulnerable to XXE injection attacks.
CollabNet Subversion Edge Management Missing Password Check
The management frontend does not require the old password for changing the password to a new one. An authenticated attacker may perform password setting attacks via XSRF without knowing the current password. An attacker that stole a Session ID (cookie) is able to gain persistent access by changing the password. Fixed in version 5.0. Version 4.0.11 is affected.
CollabNet Subversion Edge Management listViewItem LFI
The CollabNet Subversion Edge Management Frontend allows authenticated admins to read arbitrary local files via logfile “listViewItem” parameter of the “index” action. Fixed in version 5.0. Version 4.0.11 is affected.
CollabNet Subversion Edge Management Show LFI
The CollabNet Subversion Edge Management Frontend allows authenticated admins to read arbitrary local files via logfile “filename” parameter of the show action. Fixed in version 5.0. Version 4.0.11 is affected.
CollabNet Subversion Edge Management Brute Forcing
The CollabNet Subversion Edge Management Frontend does not protect against brute forcing accounts. An attacker has infinite tries to guess a valid user password. Fixed in version 5.0. Version 4.0.11 is affected.
Courier Heap Overflow / Out Of Bounds Read Access
Courier mail server versions before 0.75 suffer from out of bounds read access and heap overflow vulnerabilities.
CollabNet Subversion Edge Management Multiple Logins
The CollabNet Subversion Edge Management web application does not restrict users to be logged in only once and does not provide a configuration option to configure this feature for admins and/or user accounts. Fixed in version 5.0. Version 4.0.11 is affected.
CollabNet Subversion Edge Management Autocomplete Enabled
The CollabNet Subversion Edge management frontend login page password field has autocomplete enabled. This may allow an attacker to retrieve a stored password from the browsers key store. Fixed in version 5.0. Version 4.0.11 is affected.
CollabNet Subversion Edge Management Weak Password Policy
The CollabNet Subversion Edge Management does not implement a strong passwordpolicy. Passwords like “aaaaa” are allowed as the only requirement is that the password is at least 5 characters long. Fixed in version 5.0. Version 4.0.11 is affected.