Vulnerability Description
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Visam | Vbase Editor | 11.5.0.2 |
| Visam | Vbase Web-Remote | - |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsa-20-084-01MitigationThird Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-20-084-01MitigationThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-7008?
CVE-2020-7008 is a vulnerability with a CVSS score of 7.5 (HIGH). VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from loc...
How severe is CVE-2020-7008?
CVE-2020-7008 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7008?
Check the references section above for vendor advisories and patch information. Affected products include: Visam Vbase Editor, Visam Vbase Web-Remote.