HIGH

CVE-2021-38147

CVSS v3

7.5

HIGH

EPSS Score

63.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.

Technical details

Published
11/29/2021

Frequently asked questions

What is CVE-2021-38147?

Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.

Is CVE-2021-38147 actively exploited?

Active exploitation of CVE-2021-38147 has not been confirmed. The EPSS score is 63.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-38147?

CVE-2021-38147 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2021-38147 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.