漏洞信息详情
Micro Focus Fortify Audit Workbench和Micro Focus Fortify Software Security Center 安全漏洞
漏洞简介
Micro Focus Fortify Audit Workbench(AWB)和Micro Focus Fortify Software Security Center(SSC)都是英国Micro Focus公司的产品。Micro Focus Fortify Audit Workbench(AWB)是一套软件安全审计平台。Micro Focus Fortify Software Security Center(SSC)是一套软件安全管理平台。
Micro Focus Fortify AWB和Micro Focus Fortify SSC中存在XML外部实体注入漏洞。攻击者可利用该漏洞获取敏感信息的访问权限或造成拒绝服务。以下产品和版本受到影响:Micro Focus Fortify Audit Workbench 16.10版本,16.20版本,17.10版本;Micro Focus Fortify Software Security Center 16.10版本,16.20版本,17.10版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03083653
参考网址
来源:BID
链接:https://www.securityfocus.com/bid/102902
来源:CONFIRM
链接:https://softwaresupport.softwaregrp.com/document/-/facetsearch/document/KM03083653
受影响实体
- Microfocus Fortify_audit_workbench:16.10<!--2000-1-1-->
- Microfocus Fortify_audit_workbench:16.20<!--2000-1-1-->
- Microfocus Fortify_audit_workbench:17.10<!--2000-1-1-->
- Microfocus Fortify_software_security_center:16.10<!--2000-1-1-->
- Microfocus Fortify_software_security_center:16.20<!--2000-1-1-->
补丁
- Micro Focus Fortify Audit Workbench和Micro Focus Fortify Software Security Center 安全漏洞的修复措施<!--2018-2-6-->
还没有评论,来说两句吧...