PT-2021-12686 · Unknown · Execm Coreb2B Solution

Published

2021-09-07

·

Updated

2021-09-24

·

CVE-2020-7865

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ExECM CoreB2B solution (affected versions not specified)
Description: A vulnerability in the ExECM CoreB2B solution, due to improper input validation, allows an unauthenticated attacker to download and execute an arbitrary file via the httpDownload function. This could enable the attacker to hijack the vulnerable system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7865

Affected Products

Execm Coreb2B Solution