Barracuda SSL VPN contains a flaw that is due to the setSysProp.jsp script allowing unauthenticated users to manipulate Java system properties. With a specially crafted request, a remote attacker can change values for arbitrary Java system properties, which may disable access restrictions for the application programming interface (API). This will allow the attacker to cause a denial of service for the system, change administrator passwords, download configuration files and database dumps, and possibly have other unspecified impacts.
Disclosure Timeline:
Vendor Informed Date :2013-01-10
Disclosure Date :2013-01-24
Vendor Ack Date :2013-01-14
Vendor Solution Date :2013-01-23