CVE-2022-37027
Summary
| CVE | CVE-2022-37027 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-21 17:15:00 UTC |
| Updated | 2023-08-08 14:21:00 UTC |
| Description | Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user. |
Risk And Classification
Problem Types: CWE-88
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ahsay | Cloud Backup Suite | 9.1.4.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.compass-security.com/fileadmin/Research/Advisories/2022_12_CSNC-2022-009_AhsayCBS_... | MISC | www.compass-security.com | |
| Advisories - Compass Security | MISC | www.compass-security.com | |
| Download AhsayCBS Latest Version - Ahsay Backup | MISC | www.ahsay.com | |
| Welcome to Ahsay Partner Portal | CONFIRM | www.ahsay.com | |
| v9.3.2.0 Release Notes (27-Jun-2022) [Ahsay Wiki] | MISC | wiki.ahsay.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.