PT-2019-9234 · Cybozu · Cybozu Remote Service
Publicado
2019-01-09
·
Atualizado
2019-01-14
·
CVE-2018-16169
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cybozu Remote Service versions 3.0.0 through 3.1.0
Description
The issue allows remote authenticated attackers to upload and execute Java code files on the server.
Recommendations
For Cybozu Remote Service versions 3.0.0 through 3.1.0, at the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cybozu Remote Service