First published: Mon Dec 14 2020(Updated: )
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mpxj Mpxj | <8.3.5 | |
Oracle Primavera Unifier | >=17.7<=17.12 | |
Oracle Primavera Unifier | =16.1 | |
Oracle Primavera Unifier | =16.2 | |
Oracle Primavera Unifier | =18.8 | |
Oracle Primavera Unifier | =19.12 | |
Oracle Primavera Unifier | =21.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-35460.
The severity of CVE-2020-35460 is medium.
The affected software versions are Mpxj up to 8.3.5 and Oracle Primavera Unifier 17.7 to 17.12, 16.1, 16.2, 18.8, 19.12, and 21.12.
CVE-2020-35460 allows directory traversal in the zip stream handler flow, which leads to the writing of files to arbitrary locations.
Yes, you can find more information about CVE-2020-35460 at the following references: [http://www.mpxj.org/changes-report.html#a8.3.5](http://www.mpxj.org/changes-report.html#a8.3.5), [https://github.com/joniles/mpxj/commit/8eaf4225048ea5ba7e59ef4556dab2098fcc4a1d](https://github.com/joniles/mpxj/commit/8eaf4225048ea5ba7e59ef4556dab2098fcc4a1d), [https://www.oracle.com/security-alerts/cpujan2021.html](https://www.oracle.com/security-alerts/cpujan2021.html).