First published: Tue Aug 22 2017(Updated: )
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accellion Secure File Transfer Appliance | <=9_11_200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2857 is considered a critical severity vulnerability due to its potential for remote code execution.
To fix CVE-2015-2857, upgrade the Accellion File Transfer Appliance to version 9_11_210 or later.
CVE-2015-2857 affects Accellion File Transfer Appliance versions up to 9_11_200.
CVE-2015-2857 can be exploited by remote attackers to execute arbitrary code through malicious oauth_token parameters.
CVE-2015-2857 was disclosed in July 2015.