Path traversal in Encourage Technologies products - CVE-2023-28382
Published: May 26, 2023
Vulnerability identifier: #VU76576
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2023-28382
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can send a specially crafted HTTP request and read or alter arbitrary files on the system.
Affected software
ESS REC Agent Server Edition for Linux
ESS REC Agent Server Edition for Solaris
ESS REC Agent Server Edition for HP-UX
ESS REC Agent Server Edition for AIX
ESS REC Agent Server Edition for Solaris
ESS REC Agent Server Edition for HP-UX
ESS REC Agent Server Edition for AIX
How to mitigate CVE-2023-28382
Install update from vendor's website.