PT-2025-6733 · Alvaria · Unified Ip Unified Director

Victor A. Morales

·

Published

2025-02-14

·

Updated

2025-02-28

·

CVE-2024-56973

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alvaria, Inc Unified IP Unified Director versions prior to 7.2SP2
Description The issue allows a remote attacker to execute arbitrary code via the source and filename parameters to the "ProcessUploadFromURL.jsp" component.
Recommendations For versions prior to 7.2SP2, update to version 7.2SP2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "ProcessUploadFromURL.jsp" component until a patch is available. Avoid using the source and filename parameters in the affected component until the issue is resolved.

Exploit

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-56973

Affected Products

Unified Ip Unified Director