Impact
A validation flaw in the TAO 2.0 suite web features that handle file management or uploads allows an attacker who can reach the affected endpoint to attempt path traversal and read or write files outside the intended directory. This grants unauthorized access to sensitive files and could compromise confidentiality, integrity, or availability of data and the overall system.
Affected Systems
Customers using T-Systems Archivo, Buroweb, MyTAO or eStima are impacted. The vulnerability exists in any release prior to version 2602.0.0; instances of the four products running older versions must be identified and upgraded.
Risk and Exploitability
The CVSS score of 6 reflects moderate severity, and the EPSS score of < 1% indicates a very low exploitation probability. The flaw appears to be triggered through web features; based on the description, the likely attack vector is remote via the internet. An attacker who can invoke the vulnerable file‑handling endpoint—whether through a public URL or an authenticated session—may navigate the server filesystem arbitrarily, potentially exposing or damaging critical data. The vulnerability is not listed in CISA KEV, indicating no known mass exploitation at the time of reporting.
OpenCVE Enrichment