In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-11-10T00:00:00

Updated: 2024-07-06T13:52:50.136Z

Reserved: 2023-11-04T00:00:00


Link: CVE-2023-47246

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-10T06:15:30.510

Modified: 2023-11-13T17:28:37.350


Link: CVE-2023-47246

JSON object: View

cve-icon Redhat Information

No data.

CWE