Progress

Sharefile Storage Zones Controller

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 17.08.2026 13:32:45
  • Zuletzt bearbeitet 18.08.2026 04:16:43

In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the...

  • EPSS 0.26%
  • Veröffentlicht 17.08.2026 13:32:01
  • Zuletzt bearbeitet 18.08.2026 04:16:43

In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.

  • EPSS 0.65%
  • Veröffentlicht 17.08.2026 13:31:14
  • Zuletzt bearbeitet 18.08.2026 04:16:44

In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intende...

  • EPSS 0.34%
  • Veröffentlicht 21.07.2026 16:55:34
  • Zuletzt bearbeitet 24.07.2026 05:16:38

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directorie...

Medienbericht
  • EPSS 56.67%
  • Veröffentlicht 02.04.2026 13:04:38
  • Zuletzt bearbeitet 21.04.2026 00:28:12

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Medienbericht Exploit
  • EPSS 58.39%
  • Veröffentlicht 02.04.2026 13:04:00
  • Zuletzt bearbeitet 21.04.2026 00:26:13

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.