Executive brief
A vulnerability exists in Canias ERP, an enterprise resource planning platform used in manufacturing and industrial environments. An unauthenticated attacker can remotely read sensitive files from the server's filesystem. This could lead to the exposure of configuration files, credentials, or other private data, and is often used as part of a larger attack to take full control of the server.
Technical details
A path traversal vulnerability exists in the iasRequestFileEvent function within the RMI Interface of Canias ERP 8.03. The vulnerability is caused by insufficient validation of the m_strSourceFileName argument, which allows an attacker to specify absolute file paths. An unauthenticated remote attacker can exploit this by sending a crafted RMI request to the server to read arbitrary files from the underlying filesystem. This flaw is notably used as the final stage in a multi-step exploit chain to exfiltrate command output after achieving remote code execution. As of the advisory date, the vendor has not responded to disclosure attempts.
Affected products
- Industrial Application Software IAS Canias ERP 8.03
Timeline
- 2025-04: other: Vulnerability research began
- 2026-05-09: disclosed: Public disclosure of the vulnerability and exploit chain
- 2026-05-10: advisory: CVE published