Lucene search

K
cve[email protected]CVE-2023-26559
HistoryApr 14, 2023 - 1:15 p.m.

CVE-2023-26559

2023-04-1413:15:07
CWE-22
web.nvd.nist.gov
26
cve-2023-26559
oxygen xml web author
content fusion
directory traversal
vulnerability
security
nvd

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.1 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.6%

A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also fixed versions.)

Affected configurations

NVD
Node
syncoxygen_content_fusionRange<5.0.3
OR
syncoxygen_xml_web_authorRange<23.1.1.4
OR
syncoxygen_xml_web_authorRange24.0.0.024.1.0.3
OR
syncoxygen_xml_web_authorRange25.0.0.025.1.0.3

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

5.1 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.6%

Related for CVE-2023-26559