Java Runtime Options Injection Vulnerability in AhsayCBS by Ahsay
CVE-2022-37027

7.2HIGH

Key Information:

Vendor

Ahsay

Vendor
CVE Published:
21 September 2022

What is CVE-2022-37027?

AhsayCBS version 9.1.4.0 is susceptible to a vulnerability that allows authenticated users to inject arbitrary Java JVM options via the web interface. By modifying the Runtime Options, an administrator can inadvertently or intentionally enable features, such as JMX services, that may facilitate remote code execution within the system. This capability could be leveraged by an attacker with valid access to exploit the system's environment after a restart, underscoring the need for vigilant security practices.

References

EPSS Score

21% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.