Lucene search

K
jvnJapan Vulnerability NotesJVN:46895889
HistoryDec 04, 2023 - 12:00 a.m.

JVN#46895889: RakRak Document Plus vulnerable to path traversal

2023-12-0400:00:00
Japan Vulnerability Notes
jvn.jp
10
rakrak document plus
path traversal
sumitomo electric information systems co.
ltd.
cwe-22
update software
apply patch
apply workaround
affected versions

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.7 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

19.1%

RakRak Document Plus provided by Sumitomo Electric Information Systems Co., Ltd. contains a path traversal vulnerability (CWE-22).

Impact

Arbitrary files on the server may be obtained or deleted by a user of the product with specific privileges.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.
The developer released “Rakuraku Document Plus Ver.6.5.0.0” on January 17, 2024, which contains a fix for this vulnerability.

Apply the Patch
The developer released patches for the affected versions.

Apply the Workaround
The developer also recommends users apply the workaround.

For more information, refer to the information provided by the developer.

Products Affected

  • RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7
    The developer states that RakRak Document Plus Ver.6.1.1.3a is not affected by this vulnerability.

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.7 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

19.1%

Related for JVN:46895889