Executive brief
Agorum core open, an enterprise content management system, contains a security flaw that allows unauthorized individuals to force the server to make network requests to internal or external locations. This could allow an attacker to bypass firewalls to access internal systems or sensitive data that is not intended to be public. Organizations using affected versions should update to the latest patched releases to prevent unauthorized data exposure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Agorum core open due to insufficient validation of user-supplied URLs in the TunnelServlet and RSSReader.jsp components. Specifically, the 'tunnelAddress' and 'feed' parameters can be manipulated by a remote, unauthenticated attacker to force the server to initiate outbound HTTP requests. This can be leveraged to scan internal networks, access local services (loopback), or exfiltrate sensitive data from internal resources that are otherwise unreachable from the internet. The vulnerability is confirmed in version 11.9.1.3-1857 and has been addressed in versions 11.9.2 and 11.10.1.
Affected products
- agorum Software GmbH Agorum core open 11.9.1.3-1857 and earlier versions prior to 11.9.2 / 11.10.1
Timeline
- 2025-05-05: disclosed: First contact with vendor
- 2025-05-30: patched: Vendor released versions 11.9.2 and 11.10.1
- 2025-06-27: advisory: usd HeroLab advisory published
- 2025-07-18: advisory: NVD publication date