First published: Thu Feb 03 2000(Updated: )
The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Progress | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0127 is considered a medium severity vulnerability due to its potential for privilege escalation.
To fix CVE-2000-0127, ensure that access to the WSMadmin utility is properly restricted in the Webspeed configuration.
CVE-2000-0127 affects Progress Webspeed version 3.0.
CVE-2000-0127 enables remote attackers to gain unauthorized privileges through the wsisa.dll component.
A known workaround for CVE-2000-0127 is to manually disable access to the WSMadmin utility until a patch is applied.