First published: Fri Jan 02 2015(Updated: )
Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sysaid On-Premises | <=14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9436 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive files.
CVE-2014-9436 exploits an absolute path traversal vulnerability that allows attackers to read arbitrary files by manipulating the fileName parameter.
CVE-2014-9436 affects SysAid On-Premise versions prior to 14.4.2.
To mitigate CVE-2014-9436, upgrade SysAid On-Premise to version 14.4.2 or later.
CVE-2014-9436 allows remote attackers to read arbitrary files on the server, potentially exposing sensitive information.