CVE-2000-1024: Critical severity Unify eWave ServletExec vulnerability
Published Dec 11, 2000
·Updated
eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.
Affected Software
1 affected component
Unify eWave ServletExec=3.0c
Remediation
Patch Available
Event History
Dec 11, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1024?
CVE-2000-1024 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2000-1024?
To mitigate CVE-2000-1024, upgrade to a version of eWave ServletExec that is not affected, or implement access controls to restrict access to the UploadServlet.
3
What are the potential impacts of CVE-2000-1024?
If exploited, CVE-2000-1024 allows attackers to upload arbitrary files and execute commands, potentially leading to complete system compromise.
4
Which versions of eWave ServletExec are affected by CVE-2000-1024?
CVE-2000-1024 affects eWave ServletExec versions 3.0C and earlier.
5
Who is vulnerable to CVE-2000-1024?
Organizations using eWave ServletExec 3.0C and earlier are vulnerable to CVE-2000-1024.