vendor:
Remote Application Server
by:
Nicolas Markitanis - RUNESEC
N/A
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Remote Application Server
Affected Version From: 15.5 Build 16140
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2017-9447
CPE: a:parallels:remote_application_server:15.5
Platforms Tested: Windows
2018
Parallels Remote Application Server (RAS) 15.5 Path Traversal
The web interface of the Parallels Remote Application Server is vulnerable to Path Traversal. The vulnerability exists due to improper validation of the file path when requesting a resource under the 'RASHTML5Gateway' directory. A remote, unauthenticated attacker could exploit this weakness to read arbitrary files from the vulnerable system using path traversal sequences ('..\').
Mitigation:
Apply the patch released by Parallels.