Path traversal in Fsas Technologies products - CVE-2024-33620
Published: June 18, 2024
Vulnerability identifier: #VU92198
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-33620
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
FUJITSU Business Application ID Link Manager II
FUJITSU Software ID Link Manager
FUJITSU Software TIME CREATOR ID Link Manager
FUJITSU Software ID Link Manager
FUJITSU Software TIME CREATOR ID Link Manager
How to mitigate CVE-2024-33620
Install update from vendor's website.