CVE-2020-9352
Last modified
CVE-2020-9352 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. EPSS estimates a 1.89% chance of exploitation in the next 30 days.
Description
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Smartclient | Smartclient | 12.0 |
References
- https://blog.certimetergroup.com/it/articolo/security/smartclient-v12-xml-external-entity--cve-2020-9352Exploit, Third Party Advisory
- https://seclists.org/fulldisclosure/2020/Feb/18Exploit, Mailing List, Third Party Advisory
- https://blog.certimetergroup.com/it/articolo/security/smartclient-v12-xml-external-entity--cve-2020-9352Exploit, Third Party Advisory
- https://seclists.org/fulldisclosure/2020/Feb/18Exploit, Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-9352?
How severe is CVE-2020-9352?
How do I fix CVE-2020-9352?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-9345An issue was discovered in signotec signoPAD-API/Web (former…6.5
- CVE-2020-9346Zoho ManageEngine Password Manager Pro 10.4 and prior has no…8.8
- CVE-2020-9347Zoho ManageEngine Password Manager Pro through 10.x has a CS…9.8
- CVE-2020-9349The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP wi…7.5
- CVE-2020-9350Graph Builder in SAS Visual Analytics 8.5 allows XSS via a g…5.4
- CVE-2020-9351An issue was discovered in SmartClient 12.0. If an unauthent…5.3
- CVE-2020-9353An issue was discovered in SmartClient 12.0. The Remote Proc…7.5
- CVE-2020-9354An issue was discovered in SmartClient 12.0. The Remote Proc…7.5
- CVE-2020-9355danfruehauf NetworkManager-ssh before 1.2.11 allows privileg…9.8
- CVE-2020-9359KDE Okular before 1.10.0 allows code execution via an action…5.3
- CVE-2020-9361CryptoPro CSP through 5.0.0.10004 on 64-bit platforms allows…5.5
- CVE-2020-9362The Quick Heal AV parsing engine (November 2019) allows viru…7.8
Are you affected by CVE-2020-9352?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
