5.5

CVE-2019-14362

Exploit
Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated attackers to replace a file on the server via the getAttachmentDirectoryForNewAttachment inpKey value.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenbravoOpenbravo Erp Version3.0 Update-
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack0.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack10
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack10.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack10.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack10.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack11
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack11.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack12
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack12.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack12.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack13
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack13.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack13.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack14
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack14.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack14.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack15
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack15.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack15.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack16
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack16.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack16.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack16.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack17
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack17.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack17.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack17.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack18
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack18.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack18.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack18.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack18.4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack18.5
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack19
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack19.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack19.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack19.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack19.4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack2.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack2.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack2.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack2.4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack20
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack21
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack21.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack22
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack22.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack22.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack22.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack23
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack23.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack23.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack24
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack24.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack24.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack25
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack25.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack25.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack26
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack26.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack26.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack26.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack26.4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack27
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack27.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack28
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack28.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack28.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack28.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack28.4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack28.5
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack29
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack29.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack29.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack29.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack29.4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack3.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack3.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack30
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack30.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack30.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack30.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack31
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack31.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack31.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack31.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack31.4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack4.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack4.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack5
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack5.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack5.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack5.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack6
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack6.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack6.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack7
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack7.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack7.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack7.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack8
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack8.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack8.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack8.3
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack8.4
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack9
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack9.1
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack9.2
OpenbravoOpenbravo Erp Version3.0 Updatemaintenance_pack9.3
OpenbravoOpenbravo Erp Version3.0 Updatepr14q2
OpenbravoOpenbravo Erp Version3.0 Updatepr14q2.1
OpenbravoOpenbravo Erp Version3.0 Updatepr14q2.2
OpenbravoOpenbravo Erp Version3.0 Updatepr14q2.3
OpenbravoOpenbravo Erp Version3.0 Updatepr14q2.4
OpenbravoOpenbravo Erp Version3.0 Updatepr14q2.5
OpenbravoOpenbravo Erp Version3.0 Updatepr14q2.6
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3.1
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3.2
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3.3
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3.4
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3.5
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3.6
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3.7
OpenbravoOpenbravo Erp Version3.0 Updatepr14q3.8
OpenbravoOpenbravo Erp Version3.0 Updatepr14q4
OpenbravoOpenbravo Erp Version3.0 Updatepr15q1
OpenbravoOpenbravo Erp Version3.0 Updatepr15q1.1
OpenbravoOpenbravo Erp Version3.0 Updatepr15q1.2
OpenbravoOpenbravo Erp Version3.0 Updatepr15q1.3
OpenbravoOpenbravo Erp Version3.0 Updatepr15q1.4
OpenbravoOpenbravo Erp Version3.0 Updatepr15q1.5
OpenbravoOpenbravo Erp Version3.0 Updatepr15q2
OpenbravoOpenbravo Erp Version3.0 Updatepr15q2.1
OpenbravoOpenbravo Erp Version3.0 Updatepr15q2.2
OpenbravoOpenbravo Erp Version3.0 Updatepr15q2.3
OpenbravoOpenbravo Erp Version3.0 Updatepr15q2.4
OpenbravoOpenbravo Erp Version3.0 Updatepr15q2.5
OpenbravoOpenbravo Erp Version3.0 Updatepr15q2.6
OpenbravoOpenbravo Erp Version3.0 Updatepr15q3
OpenbravoOpenbravo Erp Version3.0 Updatepr15q3.1
OpenbravoOpenbravo Erp Version3.0 Updatepr15q3.2
OpenbravoOpenbravo Erp Version3.0 Updatepr15q3.3
OpenbravoOpenbravo Erp Version3.0 Updatepr15q3.4
OpenbravoOpenbravo Erp Version3.0 Updatepr15q3.5
OpenbravoOpenbravo Erp Version3.0 Updatepr15q4
OpenbravoOpenbravo Erp Version3.0 Updatepr15q4.1
OpenbravoOpenbravo Erp Version3.0 Updatepr15q4.2
OpenbravoOpenbravo Erp Version3.0 Updatepr15q4.3
OpenbravoOpenbravo Erp Version3.0 Updatepr15q4.4
OpenbravoOpenbravo Erp Version3.0 Updatepr15q4.5
OpenbravoOpenbravo Erp Version3.0 Updatepr15q4.6
OpenbravoOpenbravo Erp Version3.0 Updatepr16q1
OpenbravoOpenbravo Erp Version3.0 Updatepr16q1.1
OpenbravoOpenbravo Erp Version3.0 Updatepr16q1.2
OpenbravoOpenbravo Erp Version3.0 Updatepr16q1.3
OpenbravoOpenbravo Erp Version3.0 Updatepr16q2
OpenbravoOpenbravo Erp Version3.0 Updatepr16q2.1
OpenbravoOpenbravo Erp Version3.0 Updatepr16q2.2
OpenbravoOpenbravo Erp Version3.0 Updatepr16q2.3
OpenbravoOpenbravo Erp Version3.0 Updatepr16q2.4
OpenbravoOpenbravo Erp Version3.0 Updatepr16q3
OpenbravoOpenbravo Erp Version3.0 Updatepr16q3.1
OpenbravoOpenbravo Erp Version3.0 Updatepr16q3.2
OpenbravoOpenbravo Erp Version3.0 Updatepr16q3.3
OpenbravoOpenbravo Erp Version3.0 Updatepr16q3.4
OpenbravoOpenbravo Erp Version3.0 Updatepr16q3.5
OpenbravoOpenbravo Erp Version3.0 Updatepr16q4
OpenbravoOpenbravo Erp Version3.0 Updatepr16q4.1
OpenbravoOpenbravo Erp Version3.0 Updatepr16q4.2
OpenbravoOpenbravo Erp Version3.0 Updatepr16q4.3
OpenbravoOpenbravo Erp Version3.0 Updatepr16q4.4
OpenbravoOpenbravo Erp Version3.0 Updatepr17q1
OpenbravoOpenbravo Erp Version3.0 Updatepr17q1.1
OpenbravoOpenbravo Erp Version3.0 Updatepr17q1.2
OpenbravoOpenbravo Erp Version3.0 Updatepr17q1.3
OpenbravoOpenbravo Erp Version3.0 Updatepr17q2
OpenbravoOpenbravo Erp Version3.0 Updatepr17q2.1
OpenbravoOpenbravo Erp Version3.0 Updatepr17q2.2
OpenbravoOpenbravo Erp Version3.0 Updatepr17q2.3
OpenbravoOpenbravo Erp Version3.0 Updatepr17q2.4
OpenbravoOpenbravo Erp Version3.0 Updatepr17q3
OpenbravoOpenbravo Erp Version3.0 Updatepr17q3.1
OpenbravoOpenbravo Erp Version3.0 Updatepr17q3.2
OpenbravoOpenbravo Erp Version3.0 Updatepr17q3.3
OpenbravoOpenbravo Erp Version3.0 Updatepr17q4
OpenbravoOpenbravo Erp Version3.0 Updatepr17q4.1
OpenbravoOpenbravo Erp Version3.0 Updatepr17q4.2
OpenbravoOpenbravo Erp Version3.0 Updatepr18q1
OpenbravoOpenbravo Erp Version3.0 Updatepr18q1.1
OpenbravoOpenbravo Erp Version3.0 Updatepr18q1.2
OpenbravoOpenbravo Erp Version3.0 Updatepr18q1.3
OpenbravoOpenbravo Erp Version3.0 Updatepr18q2
OpenbravoOpenbravo Erp Version3.0 Updatepr18q2.1
OpenbravoOpenbravo Erp Version3.0 Updatepr18q2.2
OpenbravoOpenbravo Erp Version3.0 Updatepr18q2.3
OpenbravoOpenbravo Erp Version3.0 Updatepr18q3
OpenbravoOpenbravo Erp Version3.0 Updatepr18q3.1
OpenbravoOpenbravo Erp Version3.0 Updatepr18q3.2
OpenbravoOpenbravo Erp Version3.0 Updatepr18q3.3
OpenbravoOpenbravo Erp Version3.0 Updatepr18q3.4
OpenbravoOpenbravo Erp Version3.0 Updatepr18q3.5
OpenbravoOpenbravo Erp Version3.0 Updatepr18q4
OpenbravoOpenbravo Erp Version3.0 Updatepr18q4.1
OpenbravoOpenbravo Erp Version3.0 Updatepr18q4.2
OpenbravoOpenbravo Erp Version3.0 Updatepr18q4.3
OpenbravoOpenbravo Erp Version3.0 Updatepr19q1
OpenbravoOpenbravo Erp Version3.0 Updatepr19q1.1
OpenbravoOpenbravo Erp Version3.0 Updatepr19q1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.518
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvd@nist.gov 5.5 8 4.9
AV:N/AC:L/Au:S/C:P/I:P/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.