Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-47246

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.944
EPSS Ranking 100.0%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.
Ransomware Campaign
Known
Products affected by CVE-2023-47246
  • Sysaid » Sysaid » Version: N/A
    cpe:2.3:a:sysaid:sysaid:-
  • Sysaid » Sysaid » Version: 21.4.45
    cpe:2.3:a:sysaid:sysaid:21.4.45
  • Sysaid » Sysaid » Version: 22.1.64
    cpe:2.3:a:sysaid:sysaid:22.1.64
  • Sysaid » Sysaid » Version: 22.1.65
    cpe:2.3:a:sysaid:sysaid:22.1.65
  • Sysaid » Sysaid » Version: 22.3.35
    cpe:2.3:a:sysaid:sysaid:22.3.35
  • Sysaid » Sysaid » Version: 22.4.45
    cpe:2.3:a:sysaid:sysaid:22.4.45
  • Sysaid » Sysaid » Version: 23.2.14
    cpe:2.3:a:sysaid:sysaid:23.2.14
  • Sysaid » Sysaid » Version: 23.2.15
    cpe:2.3:a:sysaid:sysaid:23.2.15
  • Sysaid » Sysaid » Version: 23.3.34
    cpe:2.3:a:sysaid:sysaid:23.3.34
  • Sysaid » Sysaid » Version: 23.3.35
    cpe:2.3:a:sysaid:sysaid:23.3.35


Contact Us

Shodan ® - All rights reserved