Impact
The vulnerability is a path traversal flaw in the ASReportService component of HCL AppScan 360°. Improper handling of file paths permits an authenticated user to read or write files outside the intended directory. This can expose configuration data, reveal application structure, or allow modification of application files, which may lead to further compromise of the system.
Affected Systems
Vendors and products affected by this vulnerability include HCL Software’s AppScan 360°. No specific version ranges are listed in the CNA data; administrators should review their installed versions against vendor advisories.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity impact, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. To exploit, an attacker must first authenticate to the application and then send a crafted request to ASReportService that includes a path designed to escape the normal directory boundaries. Successful exploitation would allow the attacker to read sensitive files or corrupt application files within the restricted directory scope.
OpenCVE Enrichment