CVE-2020-9351: Medium severity SmartClient SmartClient vulnerability
An issue was discovered in SmartClient 12.0. If an unauthenticated attacker makes a POST request to /tools/developerConsoleOperations.jsp or /isomorphic/IDACall with malformed XML data in the transaction parameter, the server replies with a verbose error showing where the application resides (the absolute path).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to SmartClient tools by protecting the tools path (e.g., /tools/) with normal authentication and authorization mechanisms on the web server so only administrators or end users can access it.
- Compensating control
Deploy SmartClient 12.0 tools only into a trusted environment, as the documentation states the tools are by default available to anyone.
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9351?
The severity of CVE-2020-9351 is classified as medium due to the information disclosure risk.
How do I fix CVE-2020-9351?
To fix CVE-2020-9351, ensure that your SmartClient is updated to a version that addresses the vulnerability.
What type of vulnerability is CVE-2020-9351?
CVE-2020-9351 is an information disclosure vulnerability that allows unauthenticated attackers to reveal application details.
Which software versions are affected by CVE-2020-9351?
CVE-2020-9351 affects SmartClient version 12.0.
What could be the impact of exploiting CVE-2020-9351?
Exploiting CVE-2020-9351 could allow attackers to gain insights into the server structure and application environment.