CVE-2014-9436

SysAid On-Premise <14.4.2 - Path Traversal

Title source: llm
STIX 2.1

Description

Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile.

Exploits (1)

exploitdb WORKING POC
by Bernhard Mueller · textwebappswindows
https://www.exploit-db.com/exploits/35593

References (4)

Core 4
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35593
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/99456
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/99

Scores

EPSS 0.1454
EPSS Percentile 94.5%

Details

CWE
CWE-22
Status published
Products (1)
sysaid/sysaid < 14.4
Published Jan 02, 2015
Tracked Since Feb 18, 2026