CVE-2022-37027

HIGH

Ahsay Cloud Backup Suite - Remote Code Execution

Title source: rule

Description

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

Scores

CVSS v3 7.2
EPSS 0.0621
EPSS Percentile 90.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-88
Status published

Affected Products (1)

ahsay/cloud_backup_suite

Timeline

Published Sep 21, 2022
Tracked Since Feb 18, 2026