PT-2022-22146 · Wms · Wms

Published

2022-08-10

·

Updated

2022-08-13

·

CVE-2022-34365

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WMS version 3.7
Description The issue allows an attacker to potentially exploit a Path Traversal Vulnerability in the Device API, gaining unauthorized read access to files stored on the server filesystem with the privileges of the running web application.
Recommendations For WMS version 3.7, consider restricting access to the Device API until a patch is available. As a temporary workaround, limit the privileges of the running web application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-34365

Affected Products

Wms