CVE-2022-36431: Malicious File Upload
Published Dec 1, 2022
·Updated
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
Affected Software
1 affected component
Rocketsoftware Trufusion<7.9.6.1
Event History
Dec 1, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-36431?
CVE-2022-36431 has been assigned a moderate severity rating due to the potential for unauthorized code execution.
2
How do I fix CVE-2022-36431?
To fix CVE-2022-36431, upgrade to Rocket TRUfusion Enterprise version 7.9.6.1 or later.
3
What kind of attack vector is associated with CVE-2022-36431?
CVE-2022-36431 allows unauthenticated attackers to exploit arbitrary file upload capabilities.
4
What systems are affected by CVE-2022-36431?
CVE-2022-36431 affects Rocket TRUfusion Enterprise versions prior to 7.9.6.1.
5
What could an attacker achieve by exploiting CVE-2022-36431?
By exploiting CVE-2022-36431, an attacker could execute arbitrary code on the affected system.