CVE-2023-47246
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
10/11/2023
Last modified:
20/12/2024
Description
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:sysaid:sysaid:*:*:*:*:on-premises:*:*:* | 23.3.36 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://documentation.sysaid.com/docs/latest-version-installation-files
- https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023
- https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
- https://documentation.sysaid.com/docs/latest-version-installation-files
- https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023
- https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification