CVE-2022-37027

HIGH

Ahsay Cloud Backup Suite - Remote Code Execution

Title source: rule
STIX 2.1

Description

Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.

Scores

CVSS v3 7.2
EPSS 0.0621
EPSS Percentile 90.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-88
Status published
Products (1)
ahsay/cloud_backup_suite 9.1.4.0
Published Sep 21, 2022
Tracked Since Feb 18, 2026