• Creation
  • Validation
  • Communication & fix
  • Disclosure

BAE Systems | CVE-2021-26086 / BAE Systems | CVE-2021-26086

Kaizen reported 2021-11-27

This subdomain owned by BAE Systems are vulnerable to CVE-2021-26086

IP:
212.147.152.9
Port:
443
Detected protocol:
https
Found pom.properties through CVE-2021-26086:
#Generated by Maven
#Tue Mar 16 09:21:12 UTC 2021
version=8.15.1
groupId=com.atlassian.jira
artifactId=jira-webapp-dist
Found by JiraPlugin 2021-11-18
IP:
212.147.152.9
Port:
443
Detected protocol:
https
Found pom.properties through CVE-2021-26086:
#Generated by Maven
#Tue Mar 16 09:21:12 UTC 2021
version=8.15.1
groupId=com.atlassian.jira
artifactId=jira-webapp-dist
Found by JiraPlugin 2021-11-30
IP:
212.147.152.9
Port:
443
Detected protocol:
https
Found pom.properties through CVE-2021-26086:
#Generated by Maven
#Tue Mar 16 09:21:12 UTC 2021
version=8.15.1
groupId=com.atlassian.jira
artifactId=jira-webapp-dist
Found by JiraPlugin 2021-12-01
Report created by Kaizen  2021-11-27
Report approved by BloodyShell  2021-11-27
New PDF report generated by system 2021-11-27
Report dispatched to ...@... by system 2021-11-27
Kaizen commented 2021-12-13: approved doesn't show in report

I've rechecked the web. It seems like, BAE already patched this.

Report comment dispatched to BloodyShell by system 2021-12-13
Report comment dispatched to iampritam by system 2021-12-13
Report comment dispatched to zythop by system 2021-12-13
Report comment dispatched to fokoil by system 2021-12-13
Report comment dispatched to thLambda by system 2021-12-13
system commented 2021-12-13: approved shows in report

bip! I'm a LeakIX probe.

This issue looks like it has been resolved!

New PDF report generated by system 2021-12-13
Report comment dispatched to Kaizen by system 2021-12-13
Report comment dispatched to ai.technicalsupport@baesystems.com by system 2021-12-13
Report marked as fixed by BloodyShell  2021-12-13
Report closed by BloodyShell  2021-12-13
New PDF report generated by system 2021-12-13
Report comment c85954 approved by BloodyShell  2021-12-13
Information
Owner BAE Systems | CVE-2021-26086
Created 2021-11-27 18:36
Updated 2021-12-13 18:17
Fixed true

Contacts
a...@baesystems.com

Status
Status closed
Hosting contacted false
CERT contacted false

Download report