CVE-2007-2975: High severity Ignite Realtime Openfire vulnerability
Published Jun 1, 2007
·Updated
The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allows remote attackers to gain privileges and execute arbitrary code by accessing functionality that is exposed through DWR, as demonstrated using the downloader.
Affected Software
13 affected components
Ignite Realtime Openfire=3.2.0
Ignite Realtime Openfire=3.0.1
Ignite Realtime Openfire=2.6.1
Ignite Realtime Openfire=3.2.2
Ignite Realtime Openfire=3.2.3
Ignite Realtime Openfire=3.1.0
Ignite Realtime Openfire=3.2.1
Ignite Realtime Openfire=3.2.4
Ignite Realtime Openfire=2.6.0
Ignite Realtime Openfire<=3.3.0
Ignite Realtime Openfire=3.0.0
Ignite Realtime Openfire=2.6.2
Ignite Realtime Openfire=3.1.1
Remediation
Patch Available
Patch Available
Event History
Jun 1, 2007
CVE Published
01:30 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2975?
CVE-2007-2975 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2007-2975?
To fix CVE-2007-2975, upgrade Ignite Realtime Openfire to version 3.3.1 or later.
3
What versions of Ignite Realtime Openfire are affected by CVE-2007-2975?
CVE-2007-2975 affects Ignite Realtime Openfire versions up to and including 3.3.0.
4
What kind of attack is possible due to CVE-2007-2975?
CVE-2007-2975 allows remote attackers to gain privileges and execute arbitrary code.
5
Is there a workaround for CVE-2007-2975 if I cannot upgrade?
A workaround for CVE-2007-2975 would be to restrict access to the admin console.