CVE-2022-44635 - CVE House
Back to Database
Status published Unknown CVE-2022-44635

Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal

Vulnerability Description

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-44635

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • We would like to thank Aman Sapra, co-captain of the Super Guesser CTF team & Security researcher at CRED, for reporting this issue, and the Apache Security team for their assistance. We give kudos and karma to @Aleksandar Vidakovic for resolving this CVE.

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache Fineract
Vulnerable Versions:
Apache Fineract 1.8, Apache Fineract 1.7

Timeline

Official Publish: November 29th, 2022
Last Modified: April 25th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)