PT-2024-21791 · Veritas · Veritas Ediscovery Platform

Published

2024-02-21

·

Updated

2025-05-06

·

CVE-2024-27283

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Veritas eDiscovery Platform versions prior to 10.2.5
Description A vulnerability was discovered that allows the application administrator to upload potentially malicious files to arbitrary locations on the server where the application is installed.
Recommendations For versions prior to 10.2.5, update to version 10.2.5 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities for application administrators until a patch is applied. Restrict access to sensitive server locations to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-27283

Affected Products

Veritas Ediscovery Platform