CVE-2022-37027
HIGHAhsay Cloud Backup Suite - Remote Code Execution
Title source: ruleDescription
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.
References (5)
Scores
CVSS v3
7.2
EPSS
0.0621
EPSS Percentile
90.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-88
Status
published
Affected Products (1)
ahsay/cloud_backup_suite
Timeline
Published
Sep 21, 2022
Tracked Since
Feb 18, 2026