/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://medium.com/stolabs/security-issues-on-matera-systems-fba14d207dc9 | broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/147967 | third party advisory |