CVE-2020-35460
published 2020-12-14CVE-2020-35460: common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.83%
76.6th percentile
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joniles | mpxj | — | — |
| mpxj | mpxj | < 8.3.5 | 8.3.5 |
| mpxj | mpxj | >= 8.3.5 < 13.5.1 | 13.5.1 |
| mpxj | mpxj | >= 8.3.5 < 13.5.1 | 13.5.1 |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | — | — |
| oracle | primavera_unifier | 17.7 – 17.12 | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
MPXJ has a Potential Path Traversal Vulnerability
osv·2024-10-28·CVSS 5.3
CVE-2024-49771 [MEDIUM] MPXJ has a Potential Path Traversal Vulnerability
MPXJ has a Potential Path Traversal Vulnerability
### Impact
The patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be constructed which would not be picked up by the original fix and allow files to be written to arbitrary locations.
### Patches
The issue is addressed in MPXJ version 13.5.1
### Workarounds
Do not pass zip files to MPXJ.
### References
N/A
### Credits
Issue report and patch provided by yyjLF and sprinkle
GHSA
MPXJ has a Potential Path Traversal Vulnerability
ghsa·2024-10-28·CVSS 5.3
CVE-2024-49771 [MEDIUM] CWE-22 MPXJ has a Potential Path Traversal Vulnerability
MPXJ has a Potential Path Traversal Vulnerability
### Impact
The patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be constructed which would not be picked up by the original fix and allow files to be written to arbitrary locations.
### Patches
The issue is addressed in MPXJ version 13.5.1
### Workarounds
Do not pass zip files to MPXJ.
### References
N/A
### Credits
Issue report and patch provided by yyjLF and sprinkle
GHSA
MPXJ path Traversal vulnerability
ghsa·2020-12-18
CVE-2020-35460 [MEDIUM] CWE-22 MPXJ path Traversal vulnerability
MPXJ path Traversal vulnerability
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
OSV
MPXJ path Traversal vulnerability
osv·2020-12-18
CVE-2020-35460 [MEDIUM] MPXJ path Traversal vulnerability
MPXJ path Traversal vulnerability
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
CISA ICS
Siemens COMOS
cisa_ics·2023-11-16·CVSS 9.8
[CRITICAL] Siemens COMOS
ICS Advisory
##
Siemens COMOS
Release DateNovember 16, 2023
Alert CodeICSA-23-320-09
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/Low attack complexity
- Vendor: Siemens
- Equipment: COMOS
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Path Traversal, Out-of-bounds Write, Out-of-bounds Read, Integer Overflow or Wraparound, Use After Free, Heap-based Buffer Overflow, Cleartext Transmi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.mpxj.org/changes-report.html#a8.3.5https://github.com/joniles/mpxj/commit/8eaf4225048ea5ba7e59ef4556dab2098fcc4a1dhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttp://www.mpxj.org/changes-report.html#a8.3.5https://github.com/joniles/mpxj/commit/8eaf4225048ea5ba7e59ef4556dab2098fcc4a1dhttps://www.oracle.com/security-alerts/cpujan2021.html
2020-12-14
Published