Description
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29743 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected. |
References
History
No history.
Status: PUBLISHED
Assigner: GovTech CSG
Published:
Updated: 2024-09-16T22:35:02.277Z
Reserved: 2021-10-21T00:00:00.000Z
Link: CVE-2021-42787
No data.
Status : Modified
Published: 2022-03-10T17:44:05.807
Modified: 2024-11-21T06:28:10.580
Link: CVE-2021-42787
No data.
OpenCVE Enrichment
No data.
EUVD