Описание
Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ProductVendor Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ProductVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.7912 (исключая)
cpe:2.3:a:gridprosoftware:request_management:*:*:*:*:*:azure:*:*
EPSS
Процентиль: 89%
0.0456
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
больше 3 лет назад
Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.
EPSS
Процентиль: 89%
0.0456
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-22