CVE-2023-47246
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
- Affected products
- Sysaid On-Premise, Apache Tomcat
- Sysaid
- < 23.3.36
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 98.9% (100th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2023-11-10
CVE-2023-47246 at NVD
2 known exploits for CVE-2023-47246
Proof-of-concept code and exploit modules indexed by Sploitus