CVE-1999-0707: High severity HP Visualize Conference Ftp vulnerability
The default FTP configuration in HP Visualize Conference allows conference users to send a file to other participants without authorization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
HP Visualize Conference FTP/file-transfer componentfrom your environment.If file transfer functionality is not required, disable or uninstall the FTP/file-transfer component to eliminate the unauthorized transfer capability.
- Configuration
Change the default FTP/file-transfer configuration so that sending files between conference participants requires authentication. Do not allow anonymous or unauthenticated file transfers.
HP Visualize Conference FTP/file-transfer subsystem require_authentication_for_file_transfers = true - Compensating control
Until the configuration is changed or the component removed, block or restrict access to the FTP/file-transfer service (for example, via firewall rules or network ACLs restricting to trusted management hosts) or disable the file-transfer feature to prevent unauthorized file sends.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0707?
CVE-1999-0707 is considered a moderate severity vulnerability due to unauthorized file transfer capabilities in the default FTP configuration.
How do I fix CVE-1999-0707?
To fix CVE-1999-0707, you should update the FTP configuration to restrict file transfer permissions and ensure proper authorization is required.
What software does CVE-1999-0707 affect?
CVE-1999-0707 affects HP Visualize Conference FTP and HP-UX version 10.20.
Can CVE-1999-0707 lead to data leaks?
Yes, CVE-1999-0707 can lead to unauthorized data leakage as users may send files to others without proper authentication.
Is authentication required for file transfers in CVE-1999-0707?
No, authentication is not required by default in the FTP configuration affected by CVE-1999-0707.