VYPR

On Premise

by Sysaid

CVEs (3)

  • CVE-2023-47246CriKEVNov 10, 2023
    risk 0.90cvss 9.8epss 0.99

    In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

  • CVE-2020-10569CriApr 21, 2020
    risk 0.64cvss 9.8epss 0.03

    SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to execute commands on the system by chaining it with a GhostCat attack. NOTE: This…

  • CVE-2023-47247MedDec 25, 2023
    risk 0.28cvss 4.3epss 0.00

    In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102.