High severity7.2NVD Advisory· Published Sep 21, 2022· Updated Jun 17, 2026
CVE-2022-37027
CVE-2022-37027
Description
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Ahsay/AhsayCBSdescription
- cpe:2.3:a:ahsay:cloud_backup_suite:9.1.4.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- www.compass-security.com/fileadmin/Research/Advisories/2022_12_CSNC-2022-009_AhsayCBS_Java_Runtime_Parameter_Injection.txtnvdExploitThird Party Advisory
- wiki.ahsay.com/doku.phpnvdRelease NotesVendor Advisory
- www.ahsay.com/jsp/en/downloads/ahsay-downloads_latest-software_ahsaycbs.jspnvdProductVendor Advisory
- www.ahsay.com/partners/en/home/index.jspnvdPermissions RequiredVendor Advisory
- www.compass-security.com/en/research/advisoriesnvdThird Party Advisory
News mentions
0No linked articles in our index yet.