Executive brief
A path traversal vulnerability in SysAid On-Premise allows an attacker to write files to the Tomcat webroot. This can be leveraged to achieve remote code execution on the server.
Affected products
- SysAid SysAid On-Premise before 23.3.36
Timeline
- 2023-11-10: disclosed: CVE published by MITRE
- 2023-11-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-11-13: advisory: NVD initial analysis published
- 2023-11-01: exploited: Exploited in the wild in November 2023