DX Unified Infrastructure Management

 View Only
Expand all | Collapse all

get_sessions.jsp

  • 1.  get_sessions.jsp

    Posted Mar 30, 2020 04:08 AM
    Hi Support,

    I found that anyone can run get_sessions.jsp through the UMP and to get a list of connected users. Can i cancel it?

    By the way, we can't log in to your support site, I hope you're fine.


  • 2.  RE: get_sessions.jsp

    Posted Mar 30, 2020 08:40 AM
    my login to both support.nimsoft.com & support.broadcom.com is working. 
    not familiar with get_sessions.jsp so will look into and provide an update later.

    ------------------------------
    Support Engineer
    Broadcom
    ------------------------------



  • 3.  RE: get_sessions.jsp

    Broadcom Employee
    Posted Mar 30, 2020 08:49 AM
    see https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=35708
    If you are asking if you can disable this te answer is no, not currently.

    ------------------------------
    Gene Howard
    Principal Support Engineer
    Broadcom
    ------------------------------



  • 4.  RE: get_sessions.jsp

    Posted Mar 30, 2020 08:54 AM
    This is a very serious information security breach


  • 5.  RE: get_sessions.jsp
    Best Answer

    Posted Mar 30, 2020 09:02 AM
    The only way would be to rename the file
    location
    $\Nimsoft\probes\service\wasp\webapps\ROOT\jsp

    This KB provides a query to get the same info:
    Article Id: 34991
    How can I find a list of users logged logged into UMP?
    https://ca-broadcom.wolkenservicedesk.com/external/article?articleId=34991

    ------------------------------
    Support Engineer
    Broadcom
    ------------------------------



  • 6.  RE: get_sessions.jsp

    Posted Mar 30, 2020 11:53 AM
    Thanks


  • 7.  RE: get_sessions.jsp

    Posted Mar 30, 2020 11:54 AM
    Hi Solomon, 
    What the security issue here? 
    You can only make this call and get a result if you are a valid UMP user and logged into the UMP which requires a valid user \ pass:




    ------------------------------
    Daniel Blanco
    Enterprise Tools Team Architect
    DBlanco@alphaserveit.com
    ------------------------------



  • 8.  RE: get_sessions.jsp

    Posted Mar 30, 2020 11:59 AM
    It works without a user and password


  • 9.  RE: get_sessions.jsp

    Posted Mar 30, 2020 12:04 PM



  • 10.  RE: get_sessions.jsp

    Posted Mar 30, 2020 12:05 PM
    Edited by Solomon Melamed Mar 30, 2020 12:06 PM
    I happened to find out



  • 11.  RE: get_sessions.jsp

    Posted Mar 30, 2020 12:20 PM
    It might vary by version but in 8.51 this query returned results. 

    And agreed, this is kind of a gaping security issue - cuts in half the work it takes to guess a login. And it provides the remote IP making it much easier to spoof a connection.



  • 12.  RE: get_sessions.jsp

    Posted Mar 30, 2020 12:27 PM
    Username is displayed on this page. This is a serious problem.


  • 13.  RE: get_sessions.jsp

    Broadcom Employee
    Posted Mar 30, 2020 01:21 PM
    As of UIM/UMP v9.20, hitting that url, e.g.,  <ump>/jsp/get_sessions.jsp displays the message:

       "You must be logged in to access this page."

    It does not reveal any user info without being logged in.

    Steve


    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 14.  RE: get_sessions.jsp

    Posted Mar 30, 2020 02:49 PM
    This page shows the usernames of their IP addresses Don't you think it's serious?


  • 15.  RE: get_sessions.jsp

    Broadcom Employee
    Posted Mar 30, 2020 03:21 PM
    Yes, I have to agree but you can upgrade to 9.20 so that its no longer an issue.

    Steve

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 16.  RE: get_sessions.jsp

    Posted Mar 30, 2020 03:26 PM
    I deleted the file from UMP


  • 17.  RE: get_sessions.jsp

    Broadcom Employee
    Posted Mar 30, 2020 03:40 PM
    In your production environment? Did you rename the file location or delete the get_sessions.jsp file?

    Steve

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 18.  RE: get_sessions.jsp

    Posted Mar 31, 2020 02:29 AM
    I renamed the file and it's a production environment