According to this article, the proxy servlet is concerned by this vulnerability. Is it possible to disable this function ? If yes, do you know how ? If not, what can you advise ?
For information, moving to the last Alfresco 5.0 version is not option.
Hi Axel, Thanks for your precisions about CMIS! Could you just tell us (If you know of course!), if this threat concern only a server which is placed with others servers (intranet) or not ? Thanks!
The threat concerns any server in a networked environment. Only if the Alfresco server in question would be prevented from making any outbound HTTP(S) connection attempts would you avoid the "network / port scan" part of the vulnerability. And technically you can't restrict the file-level access to a level where you aren't still affected by the "file scan" part of the vulnerability.