WaveMaker < 6.4.6 Security Bypass

This script is Copyright (C) 2012 Tenable Network Security, Inc.


Synopsis :

A web development application hosted on the remote web server has a
security bypass vulnerability.

Description :

According to its self-reported version number, the version of
WaveMaker installed on the remote host has a security bypass
vulnerability. Any projects deployed with WaveMaker Studio before
6.4.6 are affected by this vulnerability. A remote attacker could
exploit this by requesting project services using unspecified URLs.

See also :

http://www.nessus.org/u?32760b3d
http://dev.wavemaker.com/wiki/bin/wmdoc_6.4/WM646RelNotes

Solution :

Upgrade to WaveMaker 6.4.6 or later.

Existing projects should be redeployed by WaveMaker Studio 6.4.6 or
later in order to address this issue. If redeployment is not
possible, consider the workaround referenced in the WaveMaker 6.4.6
release notes.

Risk factor :

High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 6.2
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses

Nessus Plugin ID: 60063 ()

Bugtraq ID: 54196

CVE ID: