Description
A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot of information about the application such as the variables set in the process, the Tomcat versions, library versions and underlying operation system via HTTP GET '/sitetest/english/dumpenv.jsp'.
Published: 2024-03-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The Meta4 HR system administrator should remove the following pages from the web servers facing the Internet: From M4WebServices: The folder "sitetest" (containing the dumpenv.jsp page) From M4Gateway: The page dump.jsp In future releases of Cegid Meta4 HR, these pages will be removed from the distribution since they do not offer real functionality.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27581 A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot of information about the application such as the variables set in the process, the Tomcat versions, library versions and underlying operation system via HTTP GET '/sitetest/english/dumpenv.jsp'.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-01T19:18:47.971Z

Reserved: 2024-03-19T06:44:29.035Z

Link: CVE-2024-2632

cve-icon Vulnrichment

Updated: 2024-08-01T19:18:47.971Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-19T12:15:09.307

Modified: 2024-11-21T09:10:10.750

Link: CVE-2024-2632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses