PT-2022-25028 · Unknown · Systematic Fix Adapter

Ivashchenko Sergey

·

Published

2022-09-05

·

Updated

2022-09-09

·

CVE-2022-39838

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Systematic FIX Adapter (ALFAFX) version 2.4.0.25
Description The issue allows remote file inclusion via a UNC share pathname and also enables absolute path traversal to local pathnames.
Recommendations For version 2.4.0.25, consider restricting access to UNC share pathnames and limiting absolute path traversal to prevent unauthorized file inclusion and access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-39838

Affected Products

Systematic Fix Adapter