The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added CVE-2022-36537 to its "Known Exploited Vulnerabilities Catalog" after threat actors began actively exploiting the remote code execution (RCE) flaw in attacks. CVE-2022-36537 is a high-severity (CVSS v3.1: 7.5) flaw impacting the ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1, enabling attackers to access sensitive information by sending a specially crafted POST request to the AuUploader component. "ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context," mentions CISA's description of the flaw. The flaw was discovered last year by Markus Wulftange and addressed by ZK on May 05, 2022, with version 9.6.2. ZK is an open-source Ajax Web app framework written in Java, enabling web developers to create graphical user interfaces for web applications with minimal effort and programming knowledge. The ZK framework is widely employed in projects of all types and sizes, so the flaw's impact is widespread and far-reaching. Notable examples of products using the ZK framework include ConnectWise Recover, version 2.9.7 and earlier, and ConnectWise R1SoftServer Backup Manager, version 6.16.3 and earlier. CISA set the deadline to apply the available security updates to March 20, 2023, giving federal agencies roughly three weeks to respond to the security risk and take proper action to secure their...
CISA warns of hackers exploiting ZK Java Framework RCE flaw
BleepingComputer
·Published Feb 28, 2023
·Updated
Affected Software
7 affected components
ZK Framework>=9.6.1<9.6.1
ZK Framework>=9.6.0.1<9.6.0.1
ZK Framework>=9.5.1.3<9.5.1.3
ZK Framework>=9.0.1.2<9.0.1.2
ZK Framework>=8.6.4.1<8.6.4.1
ConnectWise Recover<2.9.7
ConnectWise R1SoftServer Backup Manager<6.16.3
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a remote code execution (RCE) flaw in the ZK Java Framework that is being actively exploited by hackers.
2
What security implications are discussed in the article?
The article highlights that the flaw, identified as CVE-2022-36537, poses a high-severity risk to systems using the ZK Framework.
3
What products or software are affected by the ZK Java Framework RCE flaw?
The affected software includes the ZK Framework, ConnectWise Recover, and ConnectWise R1Soft Server Backup Manager.
4
Why has CISA added CVE-2022-36537 to its Known Exploited Vulnerabilities Catalog?
CISA added it to the catalog due to the active exploitation of the RCE flaw by threat actors.
5
What is the CVSS score of the CVE-2022-36537 vulnerability?
The CVE-2022-36537 vulnerability has a CVSS score of 7.5, indicating its high severity.