Wednesday, October 20, 2010

SAP BusinessObject: Axis2 Default Admin Password Vulnerability

Users of SAP BusinessObject

please be advised of an Axis2 Default Admin Password vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
R7-0037: [R7-0037] SAP BusinessObjects Axis2 Default Admin Password
Description:



The SAP BusinessObjects product contains a module (dswsbobje.war) which

deploys Axis2 with an administrator account which is configured with a

static password. As a result, anyone with access to the Axis2 port can

gain full access to the machine via arbitrary remote code execution.

This requires the attacker to upload a malicious web service and to

restart the instance of Tomcat. This issue may apply to other products

and vendors that embed the Axis2 component. The username is "admin" and

the password is "axis2", this is also the default for standalone Axis2

installations.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment