ASA-2019-00374 – Akamai CloudTest: Unauthenticated Remote Command Execution (RCE) due to an unsafe Java deserialization


Allele Security Alert

ASA-2019-00374

Identifier(s)

ASA-2019-00374, CVE-2019-11011

Title

Unauthenticated Remote Command Execution (RCE) due to an unsafe Java deserialization

Vendor(s)

Akamai

Product(s)

Akamai CloudTest

Affected version(s)

Akamai CloudTest versions prior to 58.30

Fixed version(s)

Akamai CloudTest versions 58.30 or later

Proof of concept

Unknown

Description

There is an unauthenticated remote command execution (RCE) vulnerability in CloudTest, that affects all versions prior to 58.30.

The discovered vulnerability existed due to an unsafe Java deserialization between certain parameters.

Technical details

Unknown

Credits

Rio Sherri

Reference(s)

CLOUDTEST VULNERABILITY (CVE-2019-11011)
https://blogs.akamai.com/sitr/2019/06/cloudtest-vulnerability-cve-2019-11011.html

CVE-2019-11011
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11011

CVE-2019-11011
https://nvd.nist.gov/vuln/detail/CVE-2019-11011

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: June 23, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.