Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker with administrative privileges to read any file on the filesystem via path traversal
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:NSouthrivertech Titan Mft Server
APPSouthrivertech< 2.0.18Southrivertech Titan Sftp Server
APPSouthrivertech< 2.0.18
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
Path Traversal
Powiązane podatności
CVE-2023-45685CRITICAL9.1PL ✓ten sam produkt
Path traversal przy rozpakowywaniu ZIP w Titan MFT i Titan SFTP Server
CVE-2023-45687HIGH8.8ten sam produkt
A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Wi...
CVE-2023-45688MEDIUM4.3ten sam produkt
Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allo...
CVE-2023-45690MEDIUM4.9ten sam produkt
Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user ...
CVE-2022-34005CRITICAL9.8PL ✓ten sam vendor
RCE przez zakodowane hasło konta SA w TitanFTP NextGen