i-net Clear Reports Security Advisory 2020-APR-06

General News

Summary

We rate the severity level of this vulnerability as critical - it is easy to exploit and provides an attacker with the ability to download any file on the server system that the i-net Clear Reports process has access to. It allows an attacker to download any file on the system that the i-net Clear Reports server process has access to, without needing to log in. If you are not in a position to replace this file or update your installation and you judge it necessary, you can apply the following mitigation, which will disable your i-net Clear Reports online Help system and thereby remove the vulnerability: To do this, enter your server’s “Configuration” module Deactivate the checkbox next to “Help” In the box that opens, click “Restart” to restart your service - or alternatively, restart your i-net Clear Reports server manually. To download the latest release of your i-net Clear Reports version, see the links in the following table: To protect against such vulnerabilities in the future, our development team has spent much time analyzing why this problem occurred and why it was not caught earlier through tests and code reviews. Your trust is deeply important to us, so rest assured that we will continue to make sure such issues are extremely rare and that if they occur, they will always be immediately dealt with and communicated to you without delay.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Software Development Reporting Software Java Technology

Linked Companies

i-net software
$1M to $5M