CVE-2021-38146 Scanner

Targets the /home/download endpoint via the SearchString JSON parameter, enabling an attacker to download arbitrary files from the server.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

1 month 3 days

Scan only one

URL

Toolbox

Wipro Holmes Orchestrator is an AI-powered automation platform used by enterprises in banking, healthcare, and utilities to streamline workflows and enhance decision-making. It integrates with existing systems via a robust API, enabling predictive analytics and operational efficiency. Multinational corporations rely on it for complex process orchestration, but its extensive functionality requires rigorous security oversight.

CVE-2021-38146 is an arbitrary file download vulnerability arising from improper input validation in the File Download API. The flaw allows absolute path traversal, enabling attackers to bypass access controls and retrieve sensitive files from the server. This occurs due to insufficient sanitization of user-supplied data before file path construction.

The vulnerability is exploited by sending a crafted POST request to the `/home/download` endpoint with a malicious `SearchString` JSON field. By manipulating this parameter, an attacker can specify arbitrary file paths, such as `/etc/passwd` or configuration files, leading to unauthorized data exposure. No authentication is required for exploitation.

Successful exploitation can result in the disclosure of sensitive data, including credentials, configuration files, and proprietary business information. This could lead to further attacks, such as lateral movement or privilege escalation, compromising the entire infrastructure. The CVSS score of 7.5 highlights the critical risk to confidentiality.

Get started to protecting your digital assets