HTTP: Progress WhatsUp Gold AppProfileImport Unrestricted File Upload

This signature detects attempts to exploit a known vulnerability against Progress. A successful attack can lead to arbitrary code execution.

Extended Description

In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE usingApm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.

Affected Products

Progress whatsup_gold

Short Name
HTTP:CTS:PROGRESS-WTUP-FL-UPLD
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
AppProfileImport CVE-2024-5008 File Gold Progress Unrestricted Upload WhatsUp
Release Date
08/30/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3739
False Positive
Rarely
Vendors

Progress

Found a potential security threat?