CVE-2021-42857: Directory Traversal Partial Write at AgentDaServlet
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected endpoint does not have any validation of the user's input that allows a malicious payload to be injected.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42857?
CVE-2021-42857 is a directory traversal vulnerability in the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet.
What is the severity level of CVE-2021-42857?
CVE-2021-42857 has a severity level of medium, with a CVSS score of 5.3.
Which software versions are affected by CVE-2021-42857?
CVE-2021-42857 affects Riverbed SteelCentral AppInternals Dynamic Sampling Agent versions 10.0.0 to 11.8.8 and 12.0.0 to 12.13.0.
How can the directory traversal vulnerability in CVE-2021-42857 be exploited?
The directory traversal vulnerability in CVE-2021-42857 can be exploited by sending a malicious payload through the "/api/appInternals/1.0/agent/da/pcf" API.
Where can I find more information about CVE-2021-42857?
More information about CVE-2021-42857 can be found at this reference link: https://aternity.force.com/customersuccess/s/article/Directory-Traversal-Partial-Write-at-AgentDaServlet-CVE-2021-42857