HIGH · 8.5

CVE-2015-2996

Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2)...

Vulnerability Description

Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of service (CPU and memory consumption) via a .. (dot dot) in the fileName parameter to calculateRdsFileChecksum.

CVSS Score

8.5

HIGH

AV:N/AC:L/Au:N/C:P/I:N/A:C
Confidentiality
PARTIAL
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
SysaidSysaid<= 15.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-2996?

CVE-2015-2996 is a vulnerability with a CVSS score of 8.5 (HIGH). Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2)...

How severe is CVE-2015-2996?

CVE-2015-2996 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-2996?

Check the references section above for vendor advisories and patch information. Affected products include: Sysaid Sysaid.