CVE-2021-42854: Directory Traversal Read/Write/Delete at PluginServlet
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42854?
CVE-2021-42854 is a vulnerability discovered in the SteelCentral AppInternals Dynamic Sampling Agent's PluginServlet, which allows directory traversal attacks.
What is the severity of CVE-2021-42854?
CVE-2021-42854 has a severity rating of critical with a score of 9.8.
Which software versions are affected by CVE-2021-42854?
Riverbed SteelCentral AppInternals Dynamic Sampling Agent versions from 10.0.0 to 12.13.0 are affected by CVE-2021-42854.
How can a malicious payload be executed with CVE-2021-42854?
CVE-2021-42854 allows a malicious payload to be executed through directory traversal vulnerabilities in the /api/appInternals/1.0/plugin/pmx API.
Is there a fix available for CVE-2021-42854?
Yes, please refer to the reference link provided for information on how to fix CVE-2021-42854.