Command Injection in Arena - CVE-2019-13521
Published: September 25, 2019
Vulnerability identifier: #VU21332
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13521
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper input validation when processing the .DOE files. A remote attacker can trick a victim to open a specially crafted .DOE file and execute arbitrary commands on the target system without prompting the user.
Affected software
Arena
Amazon Linux AMI
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Amazon Linux AMI
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
How to mitigate CVE-2019-13521
Install updates from vendor's website.
Arena - update to 16.00.01