Vulnerability Description
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected endpoint does not have any validation of the user's input that allows a malicious payload to be injected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Riverbed | Steelcentral Appinternals Dynamic Sampling Agent | >= 11.0.0, < 11.8.8 |
Related Weaknesses (CWE)
References
- https://aternity.force.com/customersuccess/s/article/Directory-Traversal-PartialThird Party Advisory
- https://aternity.force.com/customersuccess/s/article/Directory-Traversal-PartialThird Party Advisory
FAQ
What is CVE-2021-42857?
CVE-2021-42857 is a vulnerability with a CVSS score of 5.3 (MEDIUM). It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected...
How severe is CVE-2021-42857?
CVE-2021-42857 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42857?
Check the references section above for vendor advisories and patch information. Affected products include: Riverbed Steelcentral Appinternals Dynamic Sampling Agent.