Path traversal in Fsas Technologies products - CVE-2024-33620
Published: June 18, 2024
Vulnerability identifier: #VU92198
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-33620
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
FUJITSU Business Application ID Link Manager II
FUJITSU Software ID Link Manager
FUJITSU Software TIME CREATOR ID Link Manager
FUJITSU Business Application ID Link Manager II
FUJITSU Software ID Link Manager
FUJITSU Software TIME CREATOR ID Link Manager
Software vendor:
Fsas Technologies
Fsas Technologies
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Remediation
Install update from vendor's website.