Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/11514 | vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17852 | vdb entry |
http://secunia.com/advisories/12970 | third party advisory vendor advisory |
http://marc.info/?l=bugtraq&m=109876304705234&w=2 | mailing list |