An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by the console functionality on the /tools/developerConsoleOperations.jsp (or /isomorphic/IDACall) URL allows an unauthenticated attacker to overwrite files via vectors involving an XML comment and /.. path traversal.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://seclists.org/fulldisclosure/2020/Feb/18 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-23T01:32:02
Updated: 2024-08-04T10:26:16.121Z
Reserved: 2020-02-23T00:00:00
Link: CVE-2020-9354
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-23T02:15:10.367
Modified: 2024-11-21T05:40:28.440
Link: CVE-2020-9354
Redhat
No data.