First published: Thu Dec 01 2022(Updated: )
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket Software TruFusion | <7.9.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36431 has been assigned a moderate severity rating due to the potential for unauthorized code execution.
To fix CVE-2022-36431, upgrade to Rocket TRUfusion Enterprise version 7.9.6.1 or later.
CVE-2022-36431 allows unauthenticated attackers to exploit arbitrary file upload capabilities.
CVE-2022-36431 affects Rocket TRUfusion Enterprise versions prior to 7.9.6.1.
By exploiting CVE-2022-36431, an attacker could execute arbitrary code on the affected system.