First published: Sat May 07 2016(Updated: )
The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote authenticated users to execute arbitrary commands by leveraging the YUM_CLIENT restricted-user role.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accellion Secure File Transfer Appliance | <=9_11_210 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2352 has a high severity rating due to the potential for remote authenticated users to execute arbitrary commands.
To fix CVE-2016-2352, upgrade to Accellion File Transfer Appliance version 9_12_40 or later.
CVE-2016-2352 affects Accellion File Transfer Appliance versions prior to 9_12_40.
CVE-2016-2352 is a command injection vulnerability.
If an upgrade is not possible, restrict access to the YUM_CLIENT restricted-user role to prevent unauthorized command execution.