CVE-2024-33620: Path Traversal
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated remote attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33620?
CVE-2024-33620 is classified as a high severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2024-33620?
To fix CVE-2024-33620, update the affected software, FUJITSU ID Link Manager and FUJITSU Software TIME CREATOR, to the latest versions provided by Fujitsu.
Who is affected by CVE-2024-33620?
Organizations using FUJITSU ID Link Manager and FUJITSU Software TIME CREATOR without the latest patches are affected by CVE-2024-33620.
What types of information can be exposed due to CVE-2024-33620?
Exploiting CVE-2024-33620 can expose sensitive file contents stored on the server.
Is authentication required to exploit CVE-2024-33620?
No, CVE-2024-33620 can be exploited by an unauthenticated remote attacker.