CVE-2020-9354: Path Traversal
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an XML comment and /.. path traversal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9354?
CVE-2020-9354 is considered a high-severity vulnerability due to its potential for unauthenticated file overwriting.
How do I fix CVE-2020-9354?
To fix CVE-2020-9354, it is recommended to upgrade SmartClient to version 12.0 or apply the latest security patches provided by the vendor.
What kind of attack does CVE-2020-9354 enable?
CVE-2020-9354 enables attackers to perform file overwriting due to improper validation in the Remote Procedure Call functionality.
Is authentication required to exploit CVE-2020-9354?
No, CVE-2020-9354 can be exploited by unauthenticated attackers, making it particularly dangerous.
Which software versions are affected by CVE-2020-9354?
CVE-2020-9354 specifically affects SmartClient version 12.0.