CVE-2014-8114

UberFire Framework 0.3.x - Remote Code Execution and Arbitrary File Read via FileUploadServlet and FileDownloadServlet

Title source: llm
STIX 2.1

Description

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary files via vectors involving FileDownloadServlet.

References (4)

Core 4
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0234.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0235.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/88199

Scores

EPSS 0.0310
EPSS Percentile 86.4%

Details

CWE
CWE-264
Status published
Products (5)
org.uberfire/uberfire-parent 0.3.0.Beta5Maven
redhat/uberfire 0.3.0
redhat/uberfire 0.3.1
redhat/uberfire 0.3.2
redhat/uberfire 0.3.3
Published Feb 20, 2015
Tracked Since Feb 18, 2026