WEB_MISC unify eWave ServletExec upload

 

Code: p1242

Severity: Warning

 

Description: This event is generated when an attempt is made to access the Unify eWave ServletExec uploader servlet, which may lead to a web server compromise.

Impact: Serious. Execution of arbitrary code is possible.

Corrective: Examine the packet to see if a web request was being done. Try to determine if the request was by a legitimate web admin or not. Determine from the web server's configuration whether it was a threat or not (e.g., whether the web server even runs ServletExec, and if so whether it was running a vulnerable version).