PT-2022-25028 · Unknown · Systematic Fix Adapter

·

CVE-2022-39838

·

Published

2022-09-05

·

Updated

2022-09-09

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Systematic FIX Adapter (ALFAFX) version 2.4.0.25
Description The issue allows remote file inclusion via a UNC share pathname and also enables absolute path traversal to local pathnames.
Recommendations For version 2.4.0.25, consider restricting access to UNC share pathnames and limiting absolute path traversal to prevent unauthorized file inclusion and access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39838

Affected Products

Systematic Fix Adapter