First published: Thu Feb 18 2021(Updated: )
Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Metasys Reporting Engine | =2.0 | |
Johnsoncontrols Metasys Reporting Engine | =2.1 |
• Upgrade to MRE v2.2 or later. • Customers with licenses for MRE should contact their local branch office for remediation.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9050 is a Path Traversal vulnerability that exists in the Metasys Reporting Engine (MRE) Web Services.
CVE-2020-9050 allows a remote unauthenticated attacker to access and download arbitrary files from the system.
Johnsoncontrols Metasys Reporting Engine version 2.0 and 2.1 are affected by CVE-2020-9050.
CVE-2020-9050 has a severity rating of 7.5 (high).
To fix CVE-2020-9050, it is recommended to apply the necessary security patches provided by Johnson Controls.