PT-2023-21686 · Ibm+2 · Aix+2

Hayato Ushimaru

·

Publicado

2023-05-26

·

Atualizado

2025-01-15

·

CVE-2023-28382

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ESS REC Agent Server Edition for Linux versions V1.0.0 through V1.4.3 ESS REC Agent Server Edition for Solaris versions V1.1.0 through V1.4.0 ESS REC Agent Server Edition for HP-UX versions V1.1.0 through V1.4.0 ESS REC Agent Server Edition for AIX versions V1.2.0 through V1.4.1
Description A directory traversal vulnerability allows an authenticated attacker to view or alter an arbitrary file on the server.
Recommendations For ESS REC Agent Server Edition for Linux versions V1.0.0 through V1.4.3, update to a version outside of this range to resolve the issue. For ESS REC Agent Server Edition for Solaris versions V1.1.0 through V1.4.0, update to a version outside of this range to resolve the issue. For ESS REC Agent Server Edition for HP-UX versions V1.1.0 through V1.4.0, update to a version outside of this range to resolve the issue. For ESS REC Agent Server Edition for AIX versions V1.2.0 through V1.4.1, update to a version outside of this range to resolve the issue.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28382

Produtos afetados

Aix
Hp-Ux
Solaris