CVE-2022-39040: aEnrich a+HRD - Path Traversal
Published Jan 3, 2023
·Updated
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Affected Software
2 affected components
aEnrich A\+hrd=6.8
aEnrich A\+hrd=7.0
Event History
Jan 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-39040?
CVE-2022-39040 is considered a high severity vulnerability due to its potential for unauthenticated remote exploitation.
2
How do I fix CVE-2022-39040?
To mitigate CVE-2022-39040, update to the latest versions of aEnrich a+HRD, specifically version 7.1 or later.
3
Who is affected by CVE-2022-39040?
CVE-2022-39040 affects users of aEnrich a+HRD versions 6.8 and 7.0.
4
What type of vulnerability is CVE-2022-39040?
CVE-2022-39040 is a path traversal vulnerability that can allow unauthorized file access.
5
Can CVE-2022-39040 be exploited remotely?
Yes, CVE-2022-39040 can be exploited remotely by an unauthenticated attacker.