49335Third-party advisory
http://secunia.com/advisories/49335 CVE-2012-3347
Ransomware
AutoFORM PDM Archive before 7.0 Remote Security Bypass
Record summary
CVE-2012-3347 has a selected CVSS score of 6.0. VulnCheck reports CVE-2012-3347 use in known ransomware campaigns.
Description
AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users to bypass intended access restrictions via the /jmx-console URI, and then upload and execute arbitrary JSP code via a JBoss remote-deployment mechanism, a different vulnerability than CVE-2012-1828.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 25, 2016 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
autoform_pdm_archiveBrowse efstechnology / autoform_pdm_archive | VulnCheck | Version data not supplied | |
References
4VU#773035Third-party advisory
http://www.kb.cert.org/vuls/id/773035 kb.cert.orgConfirmation
http://www.kb.cert.org/vuls/id/MAPG-8RQL83 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-3347