A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files and exposing sensitive information disclosure.
History

Thu, 26 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 11:15:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an authenticated high privileged user to issue malicious ePO post requests to System Information Reporter, leading to creation of files anywhere on the filesystem and possibly overwriting existing files and exposing sensitive information disclosure.
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 0, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published: 2025-06-26T11:08:53.374Z

Updated: 2025-06-26T12:59:09.547Z

Reserved: 2025-04-16T13:29:50.629Z

Link: CVE-2025-3722

cve-icon Vulnrichment

Updated: 2025-06-26T12:59:06.503Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-26T11:15:26.427

Modified: 2025-06-26T18:57:43.670

Link: CVE-2025-3722

cve-icon Redhat

No data.