Note: Object First will continue to update this vulnerability as new information becomes available.
This vulnerability is related to the Object First Ootbi BETA version, which is not released for production and therefore has no impact on the production environment. The production-ready Object First Ootbi version will have this vulnerability fixed.
A flaw was found in Web Service, which could lead to local information disclosure. The command which creates the URL for the support bundle uses insecure RNG. That can lead to predicting of generated URL.
As a result, an attacker can get access to system logs. An attacker should know the credentials to exploit this vulnerability.
|CVSS 3.x Score
Object First Ootbi BETA build 184.108.40.2062
Not affected versions:
Object First Ootbi 220.127.116.1143
Software Versions and Fixes
Fixed in Object First Ootbi BETA build 18.104.22.1681
Update to Object First Ootbi BETA build 22.214.171.1241 or higher
Obtaining Software Fixes
Software updates will be available in Object First Update Manager. You can contact Support directly via email at firstname.lastname@example.org or via phone at +1 800 6657145.
Status of Notice
Object First will continue to update information regarding this vulnerability as new details become available.
This vulnerability article should be considered as the single source of current, up-to-date, authorized and accurate information posted by Object First Software.
|Initial Public Release and Final Status
|Added CVE number and NVD reference
|Added Beta note
|Adjusted build and product names