Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the intended folders. This is also known as OCMP-6592.
References
Configurations
History
21 Nov 2024, 08:26
Type | Values Removed | Values Added |
---|---|---|
References | () https://networks.unify.com/security/advisories/OBSO-2306-02.pdf - Vendor Advisory | |
References | () https://www.news.de/technik/857003738/unify-openscape-common-management-platform-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-update-zu-bekannten-schwachstellen-und-sicherheitsluecken-vom-03-07-2023/1/ - Press/Media Coverage |
12 Oct 2023, 18:36
Type | Values Removed | Values Added |
---|---|---|
First Time |
Atos
Atos unify Openscape Common Management |
|
CPE | cpe:2.3:a:atos:unify_openscape_common_management:10:-:*:*:*:*:*:* | |
References | (MISC) https://networks.unify.com/security/advisories/OBSO-2306-02.pdf - Vendor Advisory | |
References | (MISC) https://www.news.de/technik/857003738/unify-openscape-common-management-platform-gefaehrdet-it-sicherheitswarnung-vom-bsi-und-bug-report-update-zu-bekannten-schwachstellen-und-sicherheitsluecken-vom-03-07-2023/1/ - Press/Media Coverage | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CWE | CWE-22 |
09 Oct 2023, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-09 04:15
Updated : 2024-11-21 08:26
NVD link : CVE-2023-45352
Mitre link : CVE-2023-45352
CVE.ORG link : CVE-2023-45352
JSON object : View
Products Affected
atos
- unify_openscape_common_management
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')