CVE-2014-5393: Path Traversal
Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5393?
CVE-2014-5393 is considered a medium severity vulnerability due to its ability to allow remote authenticated users to access arbitrary files.
How do I fix CVE-2014-5393?
To fix CVE-2014-5393, upgrade to JobScheduler version 1.6.4246 or 1.7.x version 1.7.4241 or later.
What type of attack can exploit CVE-2014-5393?
CVE-2014-5393 can be exploited through directory traversal attacks by authenticated users with specific permissions.
Which versions of JobScheduler are affected by CVE-2014-5393?
CVE-2014-5393 affects JobScheduler versions earlier than 1.6.4246 and 1.7.x versions before 1.7.4241.
What permissions are required to exploit CVE-2014-5393?
Exploiting CVE-2014-5393 requires authenticated users to have the 'info' permission.