Xerox DocuShare Bugs Allow Data Leaks
#1
Information 
Quote:Xerox issued a fix for two vulnerabilities impacting its market-leading DocuShare enterprise document management platform. The bugs, if exploited, could expose DocuShare users to an attack resulting in the loss of sensitive data.
 
On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) issued a security bulletin urging users and administrators to apply a patch that plugged two security holes in recently released versions (6.6.1, 7.0, and 7.5) of Xerox’s DocuShare. The vulnerability is rated important.
 
Tracked as CVE-2020-27177, Xerox said the vulnerabilities open Solaris, Linux and Windows DucuShare users up to both a server-side request forgery (SSRF) attack and an unauthenticated external XML entity injection attack (XXE). Xerox issued its security advisory (XRX20W) on November 30.
 
Xerox did not share the specifics of the bugs or possible attack scenarios. In its “Mini Bulletin” it offered links to hotfix links to tarball files addressing bugs in affected versions of Solaris, Linux and Windows DocuShare.
However, a hotfix for the Solaris version of DocuShare 7.5 is not available. Xerox did not return press inquiries ahead of this published news article.

Read more: https://threatpost.com/xerox-docushare-bugs/161791/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Forced bios update
Hey! I’ve run into s...BrynnD — 10:03
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 07:34
Surfshark VPN : Award-winning VPN servi...
How to unblock block...jasonX — 07:11
K-Lite Codec Pack 19.6.8 / 19.6.8 Update
Changes in 19.6.8:...harlan4096 — 07:02
AdGuard for Windows 7.22.7
AdGuard for Window...harlan4096 — 07:01

[-]
Birthdays
Today's Birthdays
avatar (45)wapedDow
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo

[-]
Online Staff
There are no staff members currently online.

>