Impact
The vulnerability in PowerJob’s Transport Endpoint allows an attacker to supply arbitrary URLs to the MuConnectionManager.getOrCreateConnection method. A crafted request is subsequently made by the server on the attacker's behalf, enabling the attacker to reach internal network resources and potentially sensitive systems. The flaw can be activated remotely and may lead to leakage of data or use of internal services for further attacks. This type of weakness permits the execution of arbitrary web requests without the user's consent.
Affected Systems
The flaw affects the PowerJob product, specifically its server component up to and including version 5.1.2. Users running any of these versions of PowerJob, particularly configurations that expose the TestController endpoint, are susceptible.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the vulnerability’s exploitability is high because a public exploit is available and it can be triggered via a simple HTTP request sent to the vulnerable endpoint. Exact EPSS data is not available, but the vulnerability is not listed in CISA’s KEV catalog. Attackers can remotely target any instance of the vulnerable PowerJob server that is reachable on the network, and the SSRF nature of the flaw makes it an attractive vector for pivoting into internal infrastructure.
OpenCVE Enrichment