CVE-2021-42787: Directory Traversal Write/Delete/Partial Read at AgentConfigurationServlet
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42787?
CVE-2021-42787 is a directory traversal vulnerability in the SteelCentral AppInternals Dynamic Sampling Agent's AgentConfigurationServlet.
How severe is CVE-2021-42787?
CVE-2021-42787 has a severity rating of 9.8 (critical).
What software is affected by CVE-2021-42787?
The Riverbed Steelcentral Appinternals Dynamic Sampling Agent versions 10.0.0, 11.x, and 12.x are affected by CVE-2021-42787.
How can I fix CVE-2021-42787?
To fix CVE-2021-42787, it is recommended to update the affected software to a version that is not vulnerable.
Where can I find more information about CVE-2021-42787?
You can find more information about CVE-2021-42787 at the following reference link: [CVE-2021-42787 Reference](https://aternity.force.com/customersuccess/s/article/Directory-Traversal-Write-Delete-Partial-Read-at-AgentConfigurationServlet-CVE-2021-42787)