Description
Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /cwmp/happyaxis.jsp. The page discloses Java system properties, server path details, and version information to unauthorized users, resulting in information disclosure that could aid further compromise.
Problem types
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
Any version before 6.40.05
Credits
Alex Williams from Pellera Technologies
References
aggregate.digital/downloads.html
aggregate.digital/products/network-manager.html
www.vulncheck.com/...ork-manager-system-information-exposure