CVE-2021-38147
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 53.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 53.01% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- wipro/holmes
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/165039/Wipro-Holmes-Orchestrator-20.4.1-Report-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://www.wipro.com/holmes/Product
- http://packetstormsecurity.com/files/165039/Wipro-Holmes-Orchestrator-20.4.1-Report-Disclosure.htmlExploit, Third Party Advisory, VDB Entry
- https://www.wipro.com/holmes/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.