Impact
The vulnerability is a path traversal flaw that can allow an attacker to read arbitrary files on the server hosting Tanium Comply. By manipulating request paths, an attacker could access sensitive configuration files or other data that should not be exposed, potentially leading to data theft or further compromise. The weakness is categorized as CWE‑22, a classic example of path manipulation weaknesses.
Affected Systems
Tanium’s Comply application is affected. No specific product versions are listed in the CVE data, so all deployments of Tanium Comply are potentially vulnerable until a patch is applied.
Risk and Exploitability
The score of 8.5 on the CVSS scale indicates a high severity, and although the EPSS is not published, the flaw’s nature suggests a moderate exploitation probability. It is not currently listed in the CISA KEV catalog. The likely attack vector is remote, via HTTP or HTTPS requests to the Comply web service, where an attacker can craft a malicious path to exfiltrate files. Successful exploitation could expose confidential data or aid further attacks against the infrastructure.
OpenCVE Enrichment