SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP Atlassian Jira user enumeration attempt
This rule looks for a excessive number of requests to '/secure/ViewUserHover.jspa' that exceed a threshold. Such a number of requests could indicate a potential recon attempt by an attacker.
This rule alerts when Snort detects an excessive number of requests to a Jira instance to retrieve user information.
Public information/Proof of Concept available
Known false positives, with the described conditions
It's possible that this could be considered a false positive a user unintentionally makes a high number of queries for user information.
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
MITRE::ATT&CK Framework::Enterprise::Reconnaissance::Gather Victim Host Information
Information Leak
Information Leakage happens when an attacker manipulates a system into revealing sensitive information, either through malformed input or by taking advantage of another feature of the system.
CVE-2020-14181 |
Loading description
|