CVE-2019-25714: Seeyon Office Anywhere (OA) A8 Unauthenticated Arbitrary File Write via htmlofficeservlet
Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to the web root and execute them through the web server to achieve arbitrary OS command execution with web server privileges. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-03-26 (UTC).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25714?
CVE-2019-25714 has been classified as a critical vulnerability due to its ability to allow unauthenticated remote attackers to write arbitrary files to the server.
How do I fix CVE-2019-25714?
To mitigate CVE-2019-25714, update to the latest version of Seeyon Office Anywhere A8 where this vulnerability is addressed.
What systems are affected by CVE-2019-25714?
CVE-2019-25714 specifically affects Seeyon Office Anywhere A8 installations that expose the htmlofficeservlet endpoint.
Can CVE-2019-25714 be exploited remotely?
Yes, CVE-2019-25714 can be exploited remotely as it allows unauthenticated users to access the vulnerable endpoint.
What types of attacks can be performed using CVE-2019-25714?
CVE-2019-25714 can be exploited to perform arbitrary file write attacks, potentially leading to remote code execution or data exposure.