ZeroHour

CVE-2020-35460

CVSS 3.1
5.3 medium
EPSS
2%p78
Published
()
Modified
Description

common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

Vendors
mpxjoracle
Products
mpxj, primavera unifier
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.