[0day-rubbish] Lightstreamer Server 7.4.8 Shipped placeholder JMX/RMI credentials plus MLet remote class loading to root RCE (9.8)
Lightstreamer Server 7.4.8 ships placeholder JMX credentials that enable remote class loading and root code execution.
Researchers disclosed a flaw in Lightstreamer Server 7.4.8 build 3506 Enterprise with JMS Extender 2.1.0, scored 9.8. The distribution ships placeholder JMX/RMI credentials and exposes a cleartext RMI management connector on TCP 8888 bound to every interface. Access through that connector can lead to remote class loading and root remote code execution. No CVE or observed exploitation is stated.
- Affects Lightstreamer Server 7.4.8 Enterprise build 3506.
- Shipped placeholder credentials protect an all-interfaces RMI connector.
- Remote class loading can lead to root remote code execution.
- Disclosure score is 9.8; in-the-wild exploitation is not claimed.
Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in Lightstreamer Server 7.4.8 build 3506 ENTERPRISE (with JMS Extender 2.1.0). Type: a hard-coded placeholder credential shipped in the distribution (user_changeme / password_changeme) authenticating a cleartext RMI management connector on TCP 8888 bound to every interface; because the connector exposes createMBean, an attacker registers javax.management.loading.MLet and calls...
This source does not provide full text. Read it at seclists.org.