CVE-2023-38404: Malicious File Upload
The XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 allows an authenticated attacker to upload all types of files to the server. An authenticated attacker can then execute the malicious file to perform command execution on the remote server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38404?
CVE-2023-38404 is a vulnerability in the XPRTLD web application in Veritas InfoScale Operations Manager (VIOM) before 8.0.0.410 that allows an authenticated attacker to upload and execute malicious files on the remote server.
How severe is CVE-2023-38404?
CVE-2023-38404 has a severity score of 8.8, which is considered high.
How does CVE-2023-38404 affect Veritas InfoScale Operations Manager?
CVE-2023-38404 affects Veritas InfoScale Operations Manager versions before 8.0.0.410.
How can an attacker exploit CVE-2023-38404?
An authenticated attacker can exploit CVE-2023-38404 by uploading and executing malicious files on the remote server.
Is there a fix for CVE-2023-38404?
Yes, the fix for CVE-2023-38404 is to upgrade to Veritas InfoScale Operations Manager version 8.0.0.410 or later.