Junglewise Threat Intelligence

CVE-2023-47246: SysAid Server Path Traversal Vulnerability

CVE-2023-47246 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-11-13

Executive brief

A path traversal vulnerability in SysAid On-Premise allows an attacker to write files to the Tomcat webroot. This can be leveraged to achieve remote code execution on the server.

Affected products

  • SysAid SysAid On-Premise before 23.3.36

Timeline

  • 2023-11-10: disclosed: CVE published by MITRE
  • 2023-11-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-11-13: advisory: NVD initial analysis published
  • 2023-11-01: exploited: Exploited in the wild in November 2023