First published: Mon Jun 08 2015(Updated: )
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of service (CPU and memory consumption) via a .. (dot dot) in the fileName parameter to calculateRdsFileChecksum.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sysaid On-Premises | <=15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2996 is considered a medium-severity vulnerability due to its potential for remote exploitation and denial of service.
To fix CVE-2015-2996, upgrade SysAid Help Desk to version 15.2 or later, which addresses these directory traversal vulnerabilities.
CVE-2015-2996 affects SysAid Help Desk versions prior to 15.2, specifically up to 15.1.
CVE-2015-2996 allows attackers to read arbitrary files or potentially cause a denial of service through resource exhaustion.
CVE-2015-2996 is a remote vulnerability, allowing attackers to exploit it over the network without physical access.