Lucene search

K
nvd[email protected]NVD:CVE-2024-33620
HistoryJun 18, 2024 - 6:15 a.m.

CVE-2024-33620

2024-06-1806:15:11
CWE-36
web.nvd.nist.gov
8
vulnerability
path traversal
id link manager
fujitsu software time creator
unauthenticated remote attacker
sensitive information

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS

0

Percentile

9.0%

Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker.

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2024-33620