PT-2019-9234 · Cybozu · Cybozu Remote Service
CVE-2018-16169
·
Publicado
2019-01-09
·
Atualizado
2019-01-14
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cybozu Remote Service versions 3.0.0 through 3.1.0
Description
The issue allows remote authenticated attackers to upload and execute Java code files on the server.
Recommendations
For Cybozu Remote Service versions 3.0.0 through 3.1.0, at the moment, there is no information about a newer version that contains a fix for this issue.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cybozu Remote Service