Security Advisory

CVE-2022-39037

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-11-10 02:20:45
Last updated 2025-05-01 14:00:05
Assigner twcert
CVSS score 7.5
State PUBLISHED

Description

Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.