Source: Ministry of education information & communication security contingency platform
Publication Number | TACERT-ANA-2024101810100202 | Publication Time | 2024/10/18 10:43 |
Incident Type | ANA-Vulnerability Alert | Discovery Time | 2024/10/16 10:43 |
Impact Level | Medium | ||
[Subject] 【Vulnerability Alert】 Multiple Critical Security Vulnerabilities in Ragic Enterprise Cloud Database |
|||
[Content] Forwarded from TWCERTCC-200-202410-00000009 TWCERT/CC published on 2024-10-15 regarding critical security vulnerabilities in Ragic Enterprise Cloud Database. [Ragic Enterprise Cloud Database - Missing Authentication] (TVN-202410014, CVE-2024-9984, CVSS: 9.8): Ragic Enterprise Cloud Database lacks authentication for access to certain functions, allowing unauthenticated remote attackers to access the function and obtain arbitrary user session cookies. [Ragic Enterprise Cloud Database - Arbitrary File Upload] (TVN-202410015, CVE-2024-9985, CVSS: 8.8): Ragic Enterprise Cloud Database does not properly validate uploaded file types, allowing attackers with general privileges to upload webshells and execute arbitrary code on the remote server. Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
[Affected Platform] Enterprise Cloud Database versions prior to 2024/08/08 09:45:25 |
|||
[Recommended Actions] Update to version 2024/08/08 09:45:25 or later. |
|||
[Reference] 1.Ragic Enterprise Cloud Database - Missing Authentication:https://www.twcert.org.tw/tw/cp-132-8150-c955a-1.html 2.Ragic Enterprise Cloud Database - Arbitrary File Upload:https://www.twcert.org.tw/tw/cp-132-8152-09e81-1.html |