Impact
The vulnerability in Tanium Comply permits an attacker to manipulate file path references to bypass directory boundaries. This can lead to reading or accessing files outside the intended directory, compromising confidentiality and potentially exposing sensitive data stored on the server. The weakness is a classic path traversal flaw, identified as a high-severity flaw.
Affected Systems
The affected product is Tanium Comply, as specified by the vendor and product name in the CNA listing. No specific version ranges are listed in the data, so administrators should verify whether their current deployment of Tanium Comply is affected.
Risk and Exploitability
With a CVSS score of 8.5, the potential impact is significant. The EPSS score is not available, but the flaw is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, path traversal vulnerabilities can be exploited remotely through specially crafted requests, so the risk remains high and the likelihood of exploitation is non‑negligible.
OpenCVE Enrichment