Path traversal in Encourage Technologies products - CVE-2023-28382

 

Path traversal in Encourage Technologies products - CVE-2023-28382

Published: May 26, 2023


Vulnerability identifier: #VU76576
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H]
CVE-ID: CVE-2023-28382
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can send a specially crafted HTTP request and read or alter arbitrary files on the system.


Affected software

ESS REC Agent Server Edition for Linux
ESS REC Agent Server Edition for Solaris
ESS REC Agent Server Edition for HP-UX
ESS REC Agent Server Edition for AIX

How to mitigate CVE-2023-28382

Install update from vendor's website.


External References

Related Security Bulletins