S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-14251 Scanner

CVE-2019-14251 scanner - Absolute Path Traversal vulnerability in TEMENOS T24

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-14251
7.5
CVSS

An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a document on the server once successfully authenticated. However, an attacker can leverage downloadDocServer() to traverse the file system and access files or directories that are outside of the restricted directory because WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

TEMENOS T24 is a comprehensive banking software platform that integrates and manages all core banking capabilities, such as account management and transactions, customer management, risk and compliance, and product and channel management. It empowers banks and financial institutions to offer innovative and personalized banking experiences to their customers while reducing operational costs and risks. TEMENOS T24 is widely used by banks, credit unions, and microfinance institutions worldwide.

One of the vulnerabilities detected in TEMENOS T24 is CVE-2019-14251. This vulnerability allows attackers to access files or directories that are outside of the restricted directory by leveraging downloadDocServer() in the login page's JavaScript functions. This exploit is possible because the WealthT24/GetImage is used with the docDownloadPath and uploadLocation parameters.

If exploited, CVE-2019-14251 can lead to severe consequences for banks and financial institutions. Attackers can gain access to sensitive customer data, such as account details, personal information, and transaction history. They can also manipulate or delete critical files, disrupt banking operations, and cause reputational damage. Moreover, regulatory compliance can be compromised, resulting in legal fines and penalties.

Thanks to the pro features of the s4e.io platform, those who have read this article can stay up-to-date on vulnerabilities in their digital assets quickly and easily. s4e.io provides comprehensive vulnerability scanning, penetration testing, and compliance management services that help businesses stay ahead of evolving cyber threats. Don't wait until it's too late- protect your assets with s4e.io.

 

REFERENCES

Solution Advice

To protect against CVE-2019-14251, banks and financial institutions can take the following precautions:

  • Install the latest security patches and updates for TEMENOS T24.
  • Review and restrict user access rights and privileges to critical files and directories.
  • Implement network segmentation and firewall rules to isolate critical systems and services.
  • Use intrusion detection and prevention systems to monitor and block suspicious activities.
  • Conduct regular security audits and penetration testing to identify and remediate vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-14251 scanner - Absolute Path Traversal vulnerability in TEMENOS T24 | S4E