CVE-2004-1631

Properties

Published:
24.10.2004
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:R/AC:L/Au:NR/C:C/I:N/A:N/B:N) Approximated
    Product:
    OpenWFE: Work Flow Engine
    OpenWFE: Work Flow Engine
    OpenWFE: Work Flow Engine
    OpenWFE: Work Flow Engine
    OpenWFE: Work Flow Engine
    OpenWFE: Work Flow Engine

    Vulnerability description

    Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times to infer the results.

    References:

    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109876304705234&w=2
    BID: http://www.securityfocus.com/bid/11514
    SECUNIA: http://secunia.com/advisories/12970
    XF: http://xforce.iss.net/xforce/xfdb/17852
    BUGTRAQ: http://marc.theaimsgroup.com/?l=bugtraq&m=109876304705234&w=2