Description
In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-15162 | In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application. |
References
History
Wed, 25 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-25T19:56:42.862Z
Reserved: 2021-03-16T00:00:00.000Z
Link: CVE-2021-28485
Updated: 2024-08-03T21:47:32.867Z
Status : Modified
Published: 2023-09-14T15:15:07.827
Modified: 2024-11-21T05:59:45.883
Link: CVE-2021-28485
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD