HTTP: Apache Fineract ImagesApiResource Arbitrary File Upload

This signature detects attempts to exploit a known vulnerability against Apache Fineract ImagesApiResource. A successful attack can lead to arbitrary code execution.

Extended Description

Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We recommend users to upgrade to 1.8.1.

Affected Products

Apache fineract

References

CVE: CVE-2022-44635

Short Name
HTTP:APACHE:FINERACT-IAR-AFU
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apache Arbitrary CVE-2022-44635 File Fineract ImagesApiResource Upload
Release Date
02/01/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3568
False Positive
Unknown
Vendors

Apache

Found a potential security threat?