PT-2022-19717 · Solutions Atlantic · Solutions Atlantic Regulatory Reporting System

Eric Getchell

+1

·

Published

2022-06-02

·

Updated

2022-06-12

·

CVE-2022-29597

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Solutions Atlantic Regulatory Reporting System (RRS) version v500
Description The issue allows any authenticated user to reference internal system files within requests made to the "RRSWeb/maint/ShowDocument/ShowDocument.aspx" page. The server responds with the file contents of the internal system file requested, potentially enabling adversaries to extract sensitive data and/or files from the underlying file system, gain knowledge about the internal workings of the system, or access source code of the application.
Recommendations As a temporary workaround, consider restricting access to the "RRSWeb/maint/ShowDocument/ShowDocument.aspx" page until a patch is available. Additionally, limiting the ability of authenticated users to reference internal system files can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-29597

Affected Products

Solutions Atlantic Regulatory Reporting System