Aquaforest TIFF Server default configuration allows access to arbitrary files
Vulnerability Description
The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows. Depending on how a web application uses and configures TIFF Server, a remote attacker may be able to enumerate files or directories, traverse directories, bypass authentication, or access restricted files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-6352
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.aquaforest.com/blog/tiff-server-security-update
- https://www.aquaforest.com/blog/aquaforest-tiff-server-sunsetting
- https://www.aquaforest.com/wp-content/uploads/pdf/ts/TiffServer4.2.pdf
- https://github.com/qwell/disorder-in-the-court/blob/main/README-TylerTechnologies.md
- https://www.cisa.gov/news-events/alerts/2023/11/30/multiple-vulnerabilities-affecting-web-based-court-case-and-document-management-systems
Affected Vendor
Aquaforest
View all reports →