CVE-2021-32018

HIGH

JUMP AMS 3.6.0.04.009-2487 - Unauthenticated Arbitrary File Read via SOAP API

Title source: llm
STIX 2.1

Description

An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to an improper limitation of file loading on the server filesystem, aka directory traversal.

Scores

CVSS v3 8.5
EPSS 0.0118
EPSS Percentile 63.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

Details

CWE
CWE-22
Status published
Products (1)
jump-technology/asset_management 3.6.0.04.009-2487
Published Aug 03, 2021
Tracked Since Feb 18, 2026