CVE-2019-11397: Path Traversal
GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11397?
CVE-2019-11397 is a vulnerability in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) that allows Local File Inclusion via the FileDesc parameter.
How severe is CVE-2019-11397?
CVE-2019-11397 has a severity rating of 6.5 (medium).
Which software versions are affected by CVE-2019-11397?
RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) is affected by CVE-2019-11397.
How can I fix CVE-2019-11397?
To fix CVE-2019-11397, update RapidFlows Enterprise Application Builder to a version that has patched the vulnerability.
Where can I find more information about CVE-2019-11397?
You can find more information about CVE-2019-11397 on the RapidFlows website and in the Medium article provided.