CVE-2023-45352: Path Traversal
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the intended folders. This is also known as OCMP-6592.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-45352.
What is the affected software?
The affected software is Atos Unify OpenScape Common Management Portal V10.
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 8.8.
How can an attacker exploit this vulnerability?
An authenticated attacker can exploit this vulnerability by executing arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the intended folders.
How can I fix this vulnerability?
To fix this vulnerability, update Atos Unify OpenScape Common Management Portal to V10 R4.17.0 or V10 R5.1.0.