CVE-2022-34267
25.12.2023, 08:15
An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.Enginsight
Vendor | Product | Version |
---|---|---|
rws | worldserver | 𝑥 < 11.7.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration