Apache Synapse < 3.0.1 Remote Code Execution Vulnerability

critical Nessus Plugin ID 142226

Synopsis

The remote host is affected by a Remote Code Execution vulnerability

Description

All Apache Synapse releases previous to 3.0.1 installed on the remote host are affected by a Remote Code Execution vulnerability. This can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update to Apache Synapse 3.0.1 or later.

See Also

https://www.securityfocus.com/bid/102154

Plugin Details

Severity: Critical

ID: 142226

File Name: synapse_3_0_0.nasl

Version: 1.5

Type: local

Agent: windows, macosx, unix

Family: Misc.

Published: 11/3/2020

Updated: 10/7/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2017-15708

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:apache:synapse

Required KB Items: installed_sw/Apache Synapse

Exploit Ease: No known exploits are available

Patch Publication Date: 12/7/2017

Vulnerability Publication Date: 12/11/2017

Reference Information

CVE: CVE-2017-15708