7.5
CVSSv2

CVE-2021-42854

Published: 10/03/2022 Updated: 15/03/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

riverbed steelcentral appinternals dynamic sampling agent 10.0.0

riverbed steelcentral appinternals dynamic sampling agent

Recent Articles

Singapore uncovers four critical vulnerabilities in Riverbed software
The Register • Laura Dobberstein • 01 Jan 1970

Get our weekly newsletter Details emerge of the now-patched flaws

Singapore's Cyber Security Group, an agency charged with securing the nation's cyberspace, has uncovered four critical flaws in code from network software company Riverbed. The vulnerable application is SteelCentral AppInternals, formerly referred to as AppInternals Xpert, provided by Riverbed's Aternity division. AppInternals provides application performance monitoring and diagnostics, and is part of SteelCentral. Customers usually deploying this in their datacenter and on their cloud servers t...