Hi Kelly,

 

While I'm sure there are myriad vulnerabilities in the CMS I'm not sure why
it matters.  The CMS is an internal-use tool - it is protected by your
corporate firewalls and policies; it is not public-facing as is de rigueur
with many CMS these days.  Therefore, it is at minimum risk of attack, since
it would have to have come from inside the corporate network.  One might
think that if one could compromise the internal network there would be
bigger prizes than the CMS or the website, no? 

 

Or have I entirely missed the point??

 

Rgds,

Richard H.

 

From: reddot-cms-users@googlegroups.com
[mailto:reddot-cms-users@googlegroups.com] On Behalf Of Kelly Burns
Sent: Tuesday, 18 September 2012 12:35 AM
To: reddot-cms-users@googlegroups.com
Subject: XSS security vulnerability - anyone found a workaround yet?

 

Hi guys - I am sure somebody has run into this before; but I am at a
complete "dead end" here and need to resolve before our upcoming IT Audit.
:(

 

Our IT Audit firm found our Web Site Management Server 10.1 SP2 (with SQL
2008 db) poses a "significant security risk", in that it allows cross site
scripting (aka "XSS") to occur in the classic ASP portions of the app.
Obviously I need to correct this before our *next* audit (next month). 

 

Last September, when the audit found this info, I submitted this as a ticket
for resolution to OpenText Support. They said they would forward the issue
to development for analysis (this was a year ago).    I realized I'd not
heard back from them on this issue & checked back on it this week.  The
response was:

 

"This ticket was linked to a BUG ID: WSGMS-8216 currently there is no
resolution or much analysis on the issue, but it is now tracked by OpenText
and you can always use the aforementioned ID to track its status."

 

I searched all over OpenText KB for the bug, but it is not even listed
anyplace that I could find. I was hoping that surely somebody has had the
same issue and posted a workaround somewhere by now.  :-( Well if it exists,
I still haven't found it! 

 

Has anyone else dealt with this??  If what if anything did you do to secure
RedDot properly?

 

Thanks in Advance!

Kelly

 

 

-- 
You received this message because you are subscribed to the Google Groups
"RedDot CMS Users" group.
To view this discussion on the web visit
https://groups.google.com/d/msg/reddot-cms-users/-/oc1eLUNtT2UJ.
To post to this group, send email to reddot-cms-users@googlegroups.com
<mailto:reddot-cms-users@googlegroups.com> .
To unsubscribe from this group, send email to
reddot-cms-users+unsubscr...@googlegroups.com
<mailto:reddot-cms-users+unsubscr...@googlegroups.com> .
For more options, visit this group at
http://groups.google.com/group/reddot-cms-users?hl=en.

-- 
You received this message because you are subscribed to the Google Groups 
"RedDot CMS Users" group.
To post to this group, send email to reddot-cms-users@googlegroups.com.
To unsubscribe from this group, send email to 
reddot-cms-users+unsubscr...@googlegroups.com.
For more options, visit this group at 
http://groups.google.com/group/reddot-cms-users?hl=en.

Reply via email to