First published: Mon Nov 22 2021(Updated: )
The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wipro Holmes | =20.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38146 is a vulnerability in Wipro Holmes Orchestrator 20.4.1 that allows remote attackers to read arbitrary files.
The severity of CVE-2021-38146 is high with a score of 7.5.
CVE-2021-38146 affects Wipro Holmes Orchestrator 20.4.1 by allowing remote attackers to read arbitrary files.
To fix the CVE-2021-38146 vulnerability, update to a patched version of Wipro Holmes Orchestrator.
More information about CVE-2021-38146 can be found at the following references: [http://packetstormsecurity.com/files/164970/Wipro-Holmes-Orchestrator-20.4.1-Arbitrary-File-Download.html](http://packetstormsecurity.com/files/164970/Wipro-Holmes-Orchestrator-20.4.1-Arbitrary-File-Download.html) and [https://www.wipro.com/holmes/](https://www.wipro.com/holmes/)