| Solutionary ID: SERT-VDN-1007 |
| CVE ID: CVE-2011-3689 |
| Product: CodeMeter WebAdmin |
| Application Vendor: Wibu-Systems |
| Vendor URL: http://www.codemeter.de |
| Date discovered: 3/24/2011 |
| Discovered by: Rob Kraus and the Solutionary Engineering Research Team (SERT) |
| Vendor notification date: 4/14/2011 |
| Vendor response date: 5/06/2011 |
| Vendor acknowledgment date: 5/12/2011 |
Public disclosure date: 5/30/2011 Exploit Vectors: Local and Remote Licenses.html (BoxSerial parameter) Tested on: Windows XP SP3 Affected software versions: WebAdmin version 3.30 and 4.30 (previous versions may also be vulnerable) Impact: Successful attacks could disclose sensitive information about the user, session, and application to the attacker, resulting in a loss of confidentiality. Using XSS, an attacker could insert malicious code into a web page and entice naïve users to execute the malicious code. Fixed in: Pending - The vendor has logged the issue and anticipates a patch to be available in Autumn 2011. Remediation guidelines: Restrict access to internal network segments and monitor vendor notifications for application updates that may address and fix the issues identified. Remove the hardware dongle from the affected system when not needed. |
- Trusted Managed Security Provider | Solutionary
- Research
- Vulnerability Disclosures
- CodeMeter WebAdmin Cross-site Scripting (XSS) Vulnerability

