CVE-2020-35205

CRITICAL

Quest Policy Authority for Unified Communications 8.1.2.200 - Server-Side Request Forgery via initFile.jsp

Title source: llm
STIX 2.1

Description

Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and make outbound connections via the initFile.jsp file. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Scores

CVSS v3 9.8
EPSS 0.0191
EPSS Percentile 77.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (1)
quest/policy_authority_for_unified_communications 8.1.2.200
Published Jan 11, 2021
Tracked Since Feb 18, 2026