CVE-2021-32018

EUVD-2021-18885
An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to an improper limitation of file loading on the server filesystem, aka directory traversal.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
mitreCNA
8.5 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AC:L/AV:N/A:L/C:H/I:N/PR:L/S:C/UI:N