ZeroHour

CVE-2022-36537

KEV ransomwarelarge

Unauthenticated Information Disclosure in ZK Framework AuUploader

CISA: ZK Framework AuUploader Unspecified Vulnerability

CVSS 3.1
7.5 high
EPSS
95%p100
Published
()
KEV added
AI analysis

ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 fail to properly handle requests to the AuUploader servlet component, allowing unauthenticated attackers to access sensitive information. The flaw is triggered by sending a crafted POST request to the AuUploader endpoint over the network; no privileges or user interaction are required, and per the CVSS vector the impact is limited to confidentiality (no tampering or denial of service). An attacker gains the ability to read sensitive data served by Java web applications built on the affected ZK releases, potentially yielding details that enable follow-on intrusions. Any organization running or hosting a web application that embeds one of the affected ZK Framework versions is exposed, including third-party products that bundle the framework. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-27 with known ransomware use and required federal agencies to apply vendor updates, and its top-percentile EPSS score of 95.3% indicates a very high likelihood of continued exploitation.

What to do: Upgrade ZK Framework to a patched release per vendor instructions, replacing the affected builds (8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1 and 9.6.1). Inventory web applications and bundled products that use ZK, determine whether the AuUploader servlet is reachable, and restrict or filter access to that endpoint at the application server, reverse proxy, or WAF as an interim mitigation. Given the known ransomware-linked exploitation, prioritize patching internet-facing applications first.

Affected
zkoss ZK Framework9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2, 8.6.4.1
Estimated exposure
large≈ tens of thousands of internet-exposed Java web applications embedding ZK (estimate) — ZK is a long-established Java web framework that ships embedded inside many third-party and custom enterprise applications rather than as a standalone product with published install counts, so exposed instances plausibly number in the tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

CISA Known Exploited Vulnerability
Affected
ZK Framework AuUploader
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
zkoss
Products
zk framework
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news