CVE-2020-9050: Metasys Reporting Engine (MRE) Web Services - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Published Feb 19, 2021
·Updated
Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system.
Affected Software
2 affected components
Johnsoncontrols Metasys Reporting Engine=2.0
Johnsoncontrols Metasys Reporting Engine=2.1
Remediation
Information
• Upgrade to MRE v2.2 or later.
• Customers with licenses for MRE should contact their local branch office for remediation.
Event History
Feb 19, 2021
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-9050?
CVE-2020-9050 is a Path Traversal vulnerability that exists in the Metasys Reporting Engine (MRE) Web Services.
2
What is the impact of CVE-2020-9050?
CVE-2020-9050 allows a remote unauthenticated attacker to access and download arbitrary files from the system.
3
Which software is affected by CVE-2020-9050?
Johnsoncontrols Metasys Reporting Engine version 2.0 and 2.1 are affected by CVE-2020-9050.
4
How severe is CVE-2020-9050?
CVE-2020-9050 has a severity rating of 7.5 (high).
5
How can I fix CVE-2020-9050?
To fix CVE-2020-9050, it is recommended to apply the necessary security patches provided by Johnson Controls.