Impact
A validation flaw in the TAO 2.0 suite web features that oversee file management or uploads permits an attacker who can interact with the vulnerable endpoint to attempt path traversal, enabling access to files or directories outside the intended application scope. This can lead to reading or modifying sensitive data, compromising confidentiality, integrity, or system availability.
Affected Systems
Customers running T-Systems Archivo, Buroweb, MyTAO, or eStima in any release prior to version 2602.0.0 are vulnerable. Identifying assets running older versions and planning upgrades is essential.
Risk and Exploitability
The CVSS score of 6 indicates moderate severity while the EPSS score of < 1% suggests a very low exploitation probability. The vulnerability is not listed in CISA KEV, implying no known mass exploitation. The flaw is likely triggered through web-based file handling endpoints; remote attackers who reach these endpoints could navigate the server file system arbitrarily to read or write files beyond the intended directory.
OpenCVE Enrichment