Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicious JSP files through a path traversal in the file upload form. Attackers can exploit the 'fileName' parameter to upload a web shell and execute arbitrary commands by sending POST requests to the uploaded JSP endpoint.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 15 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Dec 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Bmc
Bmc compuware Istrobe Web
Vendors & Products Bmc
Bmc compuware Istrobe Web

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
Description Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicious JSP files through a path traversal in the file upload form. Attackers can exploit the 'fileName' parameter to upload a web shell and execute arbitrary commands by sending POST requests to the uploaded JSP endpoint.
Title Compuware iStrobe Web 20.13 Pre-Auth Remote Code Execution via File Upload
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-15T19:27:26.922Z

Reserved: 2025-12-11T00:58:28.456Z

Link: CVE-2024-58298

cve-icon Vulnrichment

Updated: 2025-12-15T19:27:23.394Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-11T22:15:51.060

Modified: 2025-12-12T15:17:31.973

Link: CVE-2024-58298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-12T08:49:53Z

Weaknesses