Total vulnerabilities in the database
AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Software | From | Fixed in |
---|---|---|
aveva / system_platform | 2020-r2_p01 | 2020-r2_p01.x |
aveva / system_platform | 2020-r2 | 2020-r2.x |
aveva / system_platform | 2020 | 2020.x |
aveva / system_platform | 2017 | 2020 |