iPlanet Web Server Brute Force Authentication Attacks Vulnerability
Publish Date: 21 lipca 2015
Severity: : High
Advisory Date: 21 lipca 2015
DESCRIPTION
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
INFORMATION EXPOSURE
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1005208