CVE-2003-0332: High severity Working Resources Inc. BadBlue vulnerability
The ISAPI extension in BadBlue 1.7 through 2.2, and possibly earlier versions, modifies the first two letters of a filename extension after performing a security check, which allows remote attackers to bypass authentication via a filename with a .ats extension instead of a .hts extension.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Configure your perimeter controls (WAF, reverse proxy, or firewall) or web server to block or deny HTTP requests where the requested filename ends with the extension ".ats" to prevent authentication bypass of the BadBlue ISAPI extension.
- Operational
Search web server and application logs for requests for filenames ending in ".ats"; investigate any occurrences for signs of attempted or successful bypass of authentication and remediate affected resources.
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0332?
CVE-2003-0332 is considered a critical vulnerability as it allows remote attackers to bypass authentication.
How do I fix CVE-2003-0332?
To fix CVE-2003-0332, update BadBlue to the latest version that resolves this issue, or disable the ISAPI extension.
What software is affected by CVE-2003-0332?
CVE-2003-0332 affects BadBlue versions 1.7 through 2.2.
Can CVE-2003-0332 lead to unauthorized access?
Yes, CVE-2003-0332 allows attackers to bypass necessary authentication, leading to unauthorized access.
Is CVE-2003-0332 a local or remote vulnerability?
CVE-2003-0332 is a remote vulnerability that can be exploited without physical access to the affected system.