CVE-2020-12146

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
05/11/2020
Last modified:
12/11/2020

Description

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:silver-peak:unity_orchestrator:*:*:*:*:*:*:*:* 8.9.11\+ (excluding)
cpe:2.3:a:silver-peak:unity_orchestrator:*:*:*:*:*:*:*:* 8.10 (including) 8.10.11\+ (excluding)
cpe:2.3:a:silver-peak:unity_orchestrator:*:*:*:*:*:*:*:* 9.0 (including) 9.0.1\+ (excluding)