S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2023-47246 Scanner

CVE-2023-47246 scanner - Path Traversal vulnerability in SysAid

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-47246
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
sysaid_on-premisesby sysaid
AFFECTED< 23.3.36SAFE ✓≥ 23.3.36
Updated Sep 10, 2026View on NVD →
Detail

SysAid is a popular IT service management solution used by many organizations worldwide. It is an efficient tool that helps businesses to streamline their IT workflow and provide better customer support. SysAid is used for IT asset management, ticketing system, remote desktop control, and much more. The product is reliable and provides an all-in-one solution for IT management.

Recently, a vulnerability has been detected in SysAid that could potentially lead to code execution. This vulnerability, with the code CVE-2023-47246, is a path traversal vulnerability that allows an attacker to exploit the system's integrity by accessing files or directories outside the web root directory. Once an attacker writes a file to the Tomcat webroot, it becomes easy to execute the code. This vulnerability could have a serious impact on organizations using the SysAid platform, as it could allow for unauthorized access to sensitive systems. 

When exploited, a path traversal vulnerability such as CVE-2023-47246 could lead to a range of potential security threats, such as data exfiltration, unauthorized access, and loss of system availability. If this vulnerability is exploited, the attacker can easily write a file to the Tomcat webroot, giving them the ability to execute arbitrary code that could potentially cause disastrous system disruptions. This vulnerability is particularly dangerous because the attacker could gain full control of the system, bypassing security protections, and accessing sensitive data or resources.

Thanks to the pro features of the s4e.io platform, individuals and organizations can easily and quickly learn about vulnerabilities in their digital assets. With its comprehensive vulnerability assessment tools and reporting features, s4e.io helps to identify vulnerabilities and reduce the risk of security breaches. By implementing proactive security measures and staying up-to-date with the latest security trends, organizations can protect themselves against threats like CVE-2023-47246 and ensure the security of their IT systems and data.

 

REFERENCES

Solution Advice

There are several precautions that organizations can take to protect against this vulnerability, including:

  • Regularly updating SysAid to the latest version
  • Limiting access to Tomcat webroot directories
  • Monitoring the system for suspicious activities
  • Implementing access controls to restrict unauthorized access
  • Conducting regular security assessments and penetration testing to identify vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-47246 scanner - Path Traversal vulnerability in SysAid | S4E