Summary
Is web page URL change a potential vulnerability as reported by Nessus scan?
Question
One of our customers scanned their software products with Nessus plugin and it reported a potential vulnerability for the FNP 11.14.1.3 lmadmin web server that they deliver with their products. Basically, this plugin looks for any changes to a web page when the URL has new parameters added like admin, debug, or test with a value of true. When admin=true is submitted to the lmadmin web server, the resulting webpage is slightly different which the Nessus plugin assumes is a vulnerability. Is that the case?
Answer
There is no vulnerability here. The "admin" URL parameter is handled by lmadmin in such a way that the HTTP client (or browser) has used it to indicate the license administration tab ("System Information"/"User Configuration"/"Alert Configuration"/"Server Configuration"/"Vendor Daemon Configuration") which has to be displayed. (It is not used to indicate whether the login is in administrator mode or not.)
When the HTTP client provides a value for the "admin" URL parameter, it gets used by lmadmin to form the request URL for the "Administration" link. If the HTTP client gives an invalid value like "true" for the "admin" URL parameter, the "Administration" link in the web-page returned by lmadmin will point to something like "http:serverName:port/true?vendor=vendorName&licenseTab=&selected=". However, since "/true" does not map to any valid administration tab, in this case, lmadmin will return an error page saying "The page you requested on Lmadmin cannot be found." upon clicking that link; but there will not be any exposure of unintended or additional functionality. Also, lmadmin's configuration (which is persisted using the "conf/server.xml" file) is in no way affected by that malformed HTTP request (that had a value of "true" for the "admin" URL parameter).
Related Articles
IMPORTANT NOTICE: Possible Security Vulnerability in FlexNet Publisher lmadmin License Server Manager 7Number of Views FlexNet Publisher lmadmin: Denial of Service Vulnerability Discovered 9Number of Views Impact of CVE-2017-5571 : Open Redirect Vulnerability in lmadmin Component of Flexera FlexNet Publisher 8Number of Views Remote Code Execution Vulnerability Remediated in lmadmin 15Number of Views Customizing Apache HTTP Server configuration using httpConfExtra for lmadmin of FlexNet Publisher 8Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago