VulnerabilityModified
CVE-2016-7843
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.
MEDIUM 5.5EPSS 3.42%
Does this matter?
Lower severity and a low EPSS score (3.42%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 3.42% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- hibara software/attachecase for java · hibara software/attachecase lite · hibara software/attachecase pro
- Source
- vultures@jpcert.or.jp
References
- http://jvn.jp/en/jp/JVN28331227/index.htmlThird Party Advisory, VDB Entry
- http://maruuofactory.life.coocan.jp/attachecase/#pathTraversalThird Party Advisory
- http://www.securityfocus.com/bid/95445Third Party Advisory, VDB Entry
- http://jvn.jp/en/jp/JVN28331227/index.htmlThird Party Advisory, VDB Entry
- http://maruuofactory.life.coocan.jp/attachecase/#pathTraversalThird Party Advisory
- http://www.securityfocus.com/bid/95445Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.