Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:IBM:COGNOS-BACKDOOR

Severity

Critical

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

IBM Cognos Server Backdoor Account Remote Code Execution default password

Release Date

2010/10/13

Update Number

1791

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+

APP: IBM Cognos Server Backdoor Account Remote Code Execution


A code execution vulnerability exists in IBM Cognos Express. The vulnerability is due to hard-coded user credentials, with manager-level permissions, installed by default in the user configuration of the bundled Tomcat server. Remote unauthenticated attackers can exploit this vulnerability by using these credentials to connect to the vulnerable server over port 19300/TCP and deploy a malicious web application on a vulnerable system. In an attack scenario, where arbitrary code is injected and executed on the target system, the behaviour of the target is dependent on the intention of the malicious code. In this case, the injected code will run with the privileges of the Tomcat server process. On Windows systems the Tomcat process runs as SYSTEM.

Extended Description

IBM Cognos Express is prone to a security-bypass vulnerability. Successful exploits may allow attackers to bypass security restrictions and execute arbitrary code with the privileges of the vulnerable application. This issue affects IBM Cognos Express 9.0.

Affected Products

  • IBM Cognos Express 9.0

References

  • BugTraq: 38084
  • CVE: CVE-2010-0557

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy & Policy
Legal Notices
Copyright© 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out