CVE-2012-2293: Path Traversal
Published Feb 6, 2013
·Updated
Directory traversal vulnerability in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allows remote authenticated users to upload files, and consequently execute arbitrary code, via a relative path.
Affected Software
5 affected components
EMC RSA Archer SmartSuite=4.3
EMC RSA Archer SmartSuite=4.5
EMC Rsa Archer Egrc=5.0
EMC Rsa Archer Egrc=5.1
EMC Rsa Archer Egrc=5.2
Event History
Feb 6, 2013
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2293?
CVE-2012-2293 is considered a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2012-2293?
To fix CVE-2012-2293, upgrade to RSA Archer GRC version 5.2SP1 or later.
3
What is the impact of CVE-2012-2293?
CVE-2012-2293 allows remote authenticated users to exploit directory traversal vulnerabilities to upload and execute arbitrary files.
4
Which versions are affected by CVE-2012-2293?
CVE-2012-2293 affects EMC RSA Archer SmartSuite versions 4.x and RSA Archer GRC versions 5.x prior to 5.2SP1.
5
Who can exploit CVE-2012-2293?
CVE-2012-2293 can be exploited by remote authenticated users who have access to the affected systems.