Summary
A vulnerability which may allow unauthenticated execution of arbitrary code, depending on system configuration, has been identified in the User Console. Specifically, this issue arises from the Data Platform's use of the .NET Remoting framework.
The vulnerability is related to a TCP Remoting Channel running on port 8084 of the User Console server. The TCP Remoting Channel facilitates configuration and management from the Data Platform Admin Console. In User Console versions below 5.5.68, if SecurityMode=1 has not been enabled, unauthenticated access to an object exposed on this channel may allow unauthorized command execution. When properly configured with authentication, this vulnerability does not pose a risk.
Fix Version and Resolution
This issue can be broken down into two components:
- The potential to execute arbitrary code without authentication.
- The exposed Remoting Channel services that, under certain conditions, do not require authentication.
In version 5.5.76, the ability to execute arbitrary code has been completely removed. Starting with version 5.5.68, the release notes introduced support for "Encryption and Authentication Enforceable for Operations Over the Remoting Service." The SecurityMode parameter ensures that only authenticated users and endpoints can interact with the Data Platform User Console's remoting services.
We encourage customers to upgrade to the latest version of the Data Platform and enable appropriate security settings as detailed in the 5.5.68 release notes.
Security Best Practices
To further protect your environment, we recommend the following:
- Ensure that only privileged and trusted users have authenticated access to the User Console server.
- Restrict network access to the User Console server through the use of firewalls or other network security mechanisms.
Credit
For identifying this issue and disclosing it to Flexera under the responsible disclosure process, we'd like to credit Tareq Tahboub of Trafford Security.
Related Articles
Disable HTTP for Flexera Data Platform and User Console UI 6Number of Views How to download Diagnostic data/Logs for Data Platform and User console 9Number of Views Steps to enable auto-apply for Data Platform and User Console patches 7Number of Views How to change the log file size in both Data Platform and User Console server 11Number of Views .NET Framework 4.7.2 requirement for Data Platform and User Console for patchset 5.5.60 and higher 12Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago