Directory Traversal Write/Delete/Partial Read at AgentConfigurationServlet
Vulnerability Description
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42787
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Darrel Huang, Bjorn Lim, Leng Kang Hao from Government Technology Agency of Singapore
More from Aternity
View All →Affected Vendor
Aternity
View all reports →