CVE-2022-47878
CVSS v3
8.8
HIGH
Score EPSS
35.7 %
probabilité d’exploitation au 2026-10-05
CISA KEV
Non
exploitation connue
Exploitation
—
statut SSVC
Description
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments.
Détails techniques
- Publiée le
- 2023-05-02
- Exploit-DB
- EDB-51426
Questions fréquentes
Qu’est-ce que CVE-2022-47878 ?
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments.
CVE-2022-47878 est-elle activement exploitée ?
Aucune exploitation active de CVE-2022-47878 n’est confirmée. Son score EPSS était de 35.7 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.
Quel est le score CVSS de CVE-2022-47878 ?
CVE-2022-47878 a un score de base CVSS v3 de 8.8 (gravité HIGH).
CVE-2022-47878 touche-t-elle votre environnement ?
Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.
Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite
Autres vulnérabilités 2022 à trier
Classées par probabilité d’exploitation (EPSS).