On September 19, 2019, the Weaver e-cology OA system was reported to contain a remote code execution vulnerability. This vulnerability exists in the BeanShell component of the Weaver OA system. This component comes with the system and allows unauthorized access. Attackers could exploit this vulnerability to directly execute arbitrary commands on the target server by calling a vulnerable interface of the BeanShell component. Currently, Weaver has released security patches to fix this vulnerability. Affected users are advised to download and install patches as soon as possible.
-
Scope of Impact
Affected Versions
- Waver E-cology 10 and earlier
Unaffected Versions
None
-
Mitigation
Official Patches
Weaver has released patches to fix this vulnerability. Affected users are advised to download and install the patches as soon as possible.
For how to download and install patches, click the following link:
https://www.weaver.com.cn/cs/securityDownload.asp
Workaround
If users cannot install patches for the time being, they can adopt the following temporary measures to protect against this vulnerability:
- Disable public access to the system.
- Configure URL access control policies.
For Weaver e-cology OA systems deployed on the public network, it is advised to configure an access control list (ACL) rule to prevent external access to the */*BshServlet/ path.
Protection with Security Products
NSFOCUS Web Application Firewall (WAF) users can set a custom rule for temporary protection.
- Inspection Object: URI-path
- Matching Relationship: Regular Expression Including
- Inspection Value: \.BshServlet
Statement
This advisory is only used to describe a potential risk. NSFOCUS does not provide any commitment or promise on this advisory. NSFOCUS and the author will not bear any liability for any direct and/or indirect consequences and losses caused by transmitting and/or using this advisory. NSFOCUS reserves all the rights to modify and interpret this advisory. Please include this statement paragraph when reproducing or transferring this advisory. Do not modify this advisory, add/delete any information to/from it, or use this advisory for commercial purposes without permission from NSFOCUS.
About NSFOCUS
NSFOCUS IB is a wholly owned subsidiary of NSFOCUS, an enterprise application and network security provider, with operations in the Americas, Europe, the Middle East, Southeast Asia and Japan. NSFOCUS IB has a proven track record of combatting the increasingly complex cyber threat landscape through the construction and implementation of multi-layered defense systems. The company’s Intelligent Hybrid Security strategy utilizes both cloud and on-premises security platforms, built on a foundation of real-time global threat intelligence, to provide unified, multi-layer protection from advanced cyber threats.
For more information about NSFOCUS, please visit:
http://www.nsfocusglobal.com.
NSFOCUS, NSFOCUS IB, and NSFOCUS, INC. are trademarks or registered trademarks of NSFOCUS, Inc. All other names and trademarks are property of their respective firms.