PT-2026-44047 · Unknown · Rayventory Scan Engine
CVE-2025-69600
·
Published
2026-05-27
·
Updated
2026-05-27
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RayVentory Scan Engine versions prior to 12.6 Update 8
Description
Command injection occurs due to an incorrectly constructed
find command query. The application searches for a Java executable using search criteria that is not properly terminated or sanitized. A local attacker can create a crafted directory structure and path to trick the application into executing arbitrary Java code. This issue is triggered via the 'getconfig', 'upload', 'inventory', and 'oracle' options. Specifically, the 'upload' option is affected through the URL argument, and the 'oracle' option is affected through the -o flag.Recommendations
Update to a version later than 12.6 Update 8.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rayventory Scan Engine