Executive brief
Agorum core open, an enterprise content management system used for document management and workflow automation, contains a security flaw in its web service component. This vulnerability allows an unauthenticated attacker to remotely access and read sensitive files stored on the server. This could lead to the exposure of system configuration files, user credentials, or proprietary business data, potentially facilitating further attacks on the organization's infrastructure.
Technical details
An absolute path traversal vulnerability (CWE-36) exists in the dynawebservice component of Agorum core open. The flaw is located in the 'getTemp' action of the '/dynawebservices/wsfiling/' endpoint, where the 'tmpFile' parameter fails to properly validate or sanitize user-supplied file paths. An unauthenticated remote attacker can exploit this by sending a specially crafted GET request containing absolute file paths (e.g., /etc/passwd), allowing them to read arbitrary files with the permissions of the application service. The vendor has addressed this in versions 11.9.2 and 11.10.1 by implementing better input validation and restricting file access to trusted locations.
Affected products
- agorum Software GmbH Agorum core open 11.9.1.3-1857 and earlier versions prior to 11.9.2 / 11.10.1
Timeline
- 2025-05-05: disclosed: Initial report to vendor
- 2025-05-15: patched: Fix applied to cloud instances
- 2025-05-30: patched: Fixed versions 11.9.2 and 11.10.1 released
- 2025-06-27: advisory: Security advisory published by usd HeroLab
- 2025-07-18: advisory: CVE published to NVD