Impact
An authenticated administrative user of Progress ShareFile Storage Zones Controller can exploit a path traversal flaw that permits reading arbitrary files, writing files to arbitrary directories, or probing the existence of files on the server. The vulnerability stems from improper validation of path components, as reflected by related CWEs. The impact includes potential disclosure of confidential data, modification of server files, or an attacker’s ability to confirm the presence of sensitive files, all of which could further enable escalation or persistence on the system.
Affected Systems
The flaw affects Progress ShareFile Storage Zones Controller in all releases prior to 5.12.5 and 6.0.2. Only versions that have not been updated to those release numbers contain the vulnerable path handling logic.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. The EPSS score indicates that exploitation is unlikely at present, but the risk is heightened by the fact that the attack requires administrative credentials, which if compromised would grant full server access. Since the vulnerability is not listed in CISA KEV, there is currently no known widespread exploitation, yet the potential impact warrants prompt action. The likely attack vector is external, achievable by any user who can authenticate as an administrator against the SZC service over the network.
OpenCVE Enrichment