The vendor explicitly identifies these products as affected by this CVE.
- Omnivise T3000 Application Server R9.2
- Omnivise T3000 R8.2 SP3
- Omnivise T3000 R8.2 SP4
- Summary
- The affected system exposes the port of an internal application on the public network interface allowing an attacker to circumvent authentication and directly access the exposed application.
- Remediation
- Install System Software Patch 22.173.20 and System Software Patch 22.173.52 as well as Application Software Patch 09.0.19.06; apply additional mitigations from Omnivise T3000 Technical News 2024-089
