Weak File Permissions in Burp Suite Enterprise Edition for Windows
CVE-2021-44230
6.5MEDIUM
What is CVE-2021-44230?
Burp Suite Enterprise Edition prior to version 2021.11 on Windows is susceptible to a vulnerability due to inadequate file permissions on its embedded H2 database. This flaw may allow an adversary, who has already compromised a valid Windows account, to gain unauthorized access to sensitive configuration, log, and database files. Consequently, this could enable further exploitation through privilege escalation for the compromised account.
