[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)
Jitterbit Agent 12.8.1.6's Docker image exposes unauthenticated SOAP with hard-coded credentials, leading to OS command execution (CVSS 9.8).
0day Rubbish Research Team disclosed that the jitterbit/agent:12.8.1.6 Docker image ships an unauthenticated SOAP interface protected by hard-coded credentials. Attackers who recover these credentials can invoke the SOAP endpoint to execute OS commands, with the issue rated CVSS 9.8. The disclosure does not mention a CVE identifier or observed exploitation in the wild.
- Unauthenticated SOAP interface with hard-coded credentials in jitterbit/agent:12.8.1.6
- Hard-coded credentials lead to OS command execution; rated CVSS 9.8
- Affects the Docker distribution of Jitterbit Agent 12.8.1.6
Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6). Type: Unauthenticated SOAP with hard-coded credentials leading...
This source does not provide full text. Read it at seclists.org.