ZeroHour
Full Disclosurepublished ()ingested 1
Part of a story covered by 2 sources: “0day Rubbish discloses two CVSS 9.8 unauthenticated SOAP command-execution flaws: DBxtra .NET 13.1.1.0 and Jitterbit Agent 12.8.1.6 (Docker)” — merged summary and timeline →

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

highVulnerabilityimportance 55
AI summary · glm-5.3-flash

Jitterbit Agent 12.8.1.6's Docker image exposes unauthenticated SOAP with hard-coded credentials, leading to OS command execution (CVSS 9.8).

0day Rubbish Research Team disclosed that the jitterbit/agent:12.8.1.6 Docker image ships an unauthenticated SOAP interface protected by hard-coded credentials. Attackers who recover these credentials can invoke the SOAP endpoint to execute OS commands, with the issue rated CVSS 9.8. The disclosure does not mention a CVE identifier or observed exploitation in the wild.

  • Unauthenticated SOAP interface with hard-coded credentials in jitterbit/agent:12.8.1.6
  • Hard-coded credentials lead to OS command execution; rated CVSS 9.8
  • Affects the Docker distribution of Jitterbit Agent 12.8.1.6
Full article

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6). Type: Unauthenticated SOAP with hard-coded credentials leading...

This source does not provide full text. Read it at seclists.org.