First published: Wed Mar 09 2022(Updated: )
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.
Credit: cve_disclosure@tech.gov.sg
Affected Software | Affected Version | How to fix |
---|---|---|
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | >=11.0.0<11.8.8 | |
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | >=12.0.0<12.13.0 | |
Riverbed Steelcentral Appinternals Dynamic Sampling Agent | =10.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42787 is a directory traversal vulnerability in the SteelCentral AppInternals Dynamic Sampling Agent's AgentConfigurationServlet.
CVE-2021-42787 has a severity rating of 9.8 (critical).
The Riverbed Steelcentral Appinternals Dynamic Sampling Agent versions 10.0.0, 11.x, and 12.x are affected by CVE-2021-42787.
To fix CVE-2021-42787, it is recommended to update the affected software to a version that is not vulnerable.
You can find more information about CVE-2021-42787 at the following reference link: [CVE-2021-42787 Reference](https://aternity.force.com/customersuccess/s/article/Directory-Traversal-Write-Delete-Partial-Read-at-AgentConfigurationServlet-CVE-2021-42787)