Executive brief
Interinfo DreamMaker, a development tool, contains a security flaw that allows unauthorized users to access sensitive system files. An attacker could exploit this to download configuration files or other private data from the server. This could lead to the exposure of credentials or intellectual property, potentially compromising the entire system.
Technical details
A relative path traversal vulnerability (CWE-23) exists in Interinfo DreamMaker Java Composer version 2.2 and earlier. The flaw allows an unauthenticated local attacker to bypass directory restrictions and read arbitrary files on the host system. By supplying specially crafted input containing traversal sequences (e.g., ../), an attacker can download sensitive system files. This vulnerability is addressed in Java Composer version 2.3. Note: While the CVSS vector indicates Network (AV:N), the description specifies local attackers.
Affected products
- Interinfo DreamMaker Java Composer 2.2 and earlier
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
- 2026-05-29: patched: Fixed in Java Composer 2.3