CVE-2014-5359: Path Traversal
Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary files via a .. (dot dot) in the GetFile parameter to owa/owa.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5359?
CVE-2014-5359 is considered a high severity vulnerability that allows remote attackers to perform directory traversal.
How do I fix CVE-2014-5359?
To fix CVE-2014-5359, upgrade the SafeNet Authentication Service Outlook Web Access Agent to version 1.03.30109 or later.
What is affected by CVE-2014-5359?
CVE-2014-5359 affects versions of the SafeNet Authentication Service Outlook Web Access Agent up to 1.03.20212.
What type of attack is possible with CVE-2014-5359?
CVE-2014-5359 allows an attacker to use directory traversal techniques to read arbitrary files on the server.
When was CVE-2014-5359 disclosed?
CVE-2014-5359 was disclosed in 2014 and affects SafeNet Authentication Service prior to version 1.03.30109.