Path traversal in MPXJ - CVE-2020-35460
Published: November 16, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the zip stream handler flow within common/InputStreamHelper.java. A remote attacker can send a specially crafted HTTP request and writr arbitrary files on the system.
Affected software
IBM TRIRIGA
Siemens COMOS
How to mitigate CVE-2020-35460
IBM TRIRIGA - addressed in versions 3.6.1.3, 3.7.0.1, 3.8.0.1, 4.0.2, 4.1.1
Siemens COMOS - update to 10.4.4