CVE-2017-7685: Medium severity Apache OpenMeetings vulnerability
Published Jul 14, 2017
·Updated
Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH.
Affected Software
21 affected components
Apache OpenMeetings=1.0.0
Apache OpenMeetings=2.0
Apache OpenMeetings=2.1
Apache OpenMeetings=2.1.1
Apache OpenMeetings=2.2.0
Apache OpenMeetings=3.0.0
Apache OpenMeetings=3.0.1
Apache OpenMeetings=3.0.2
Apache OpenMeetings=3.0.3
Apache OpenMeetings=3.0.4
Apache OpenMeetings=3.0.5
Apache OpenMeetings=3.0.6
Apache OpenMeetings=3.0.7
Apache OpenMeetings=3.1.0
Apache OpenMeetings=3.1.1
Apache OpenMeetings=3.1.2
Apache OpenMeetings=3.1.3
Apache OpenMeetings=3.1.4
Apache OpenMeetings=3.1.5
Apache OpenMeetings=3.2.0
Apache OpenMeetings=3.2.1
Event History
Jul 14, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7685?
The severity of CVE-2017-7685 is categorized as critical due to the exposure of insecure HTTP methods.
2
How do I fix CVE-2017-7685?
To fix CVE-2017-7685, disable the insecure HTTP methods PUT, DELETE, HEAD, and PATCH on your Apache OpenMeetings server.
3
Which versions are affected by CVE-2017-7685?
CVE-2017-7685 affects Apache OpenMeetings versions 1.0.0 and 2.0 to 3.2.1.
4
What can happen if CVE-2017-7685 is exploited?
If exploited, CVE-2017-7685 could allow unauthorized manipulation of data and services on the OpenMeetings server.
5
Is there a patch available for CVE-2017-7685?
No, there is no official patch for CVE-2017-7685; mitigation involves manual configuration adjustments to the server.