HIGH

CVE-2022-47878

CVSS v3

8.8

HIGH

EPSS Score

20.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments.

Technical details

Published
5/2/2023

Frequently asked questions

What is CVE-2022-47878?

Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authenticated users to specify the location as Webroot directory. Consecutive file uploads can lead to the execution of arbitrary code. NOTE: The vendor states that the vulnerability affects installations running version 22.2 or earlier. The issue was resolved with the version 22.3 and later versions are not affected. Additionally, the vendor states that this vulnerability affects on-premises deployments only and that it does not impact cloud-hosted or SaaS environments.

Is CVE-2022-47878 actively exploited?

Active exploitation of CVE-2022-47878 has not been confirmed. The EPSS score is 20.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-47878?

CVE-2022-47878 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2022-47878 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.