Sysaid
Sysaid: vulnerabilidades y CVE
Sysaid tiene 30 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 7 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE30
Últimos 12 meses0
Críticas7
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-2776 | Crítica (9.8) | 64% | ⚠ Explotación activa | 7 may 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read… |
| CVE-2025-2775 | Alta (7.5) | 43% | ⚠ Explotación activa | 7 may 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read… |
| CVE-2023-47246 | Crítica (9.8) | 99% | ⚠ Explotación activa | 10 nov 2023 | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-2777 | Crítica (9.8) | 72% | — | 7 may 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives. |
| CVE-2025-2776 | Crítica (9.8) | 64% | ⚠ Explotación activa | 7 may 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read… |
| CVE-2025-2775 | Alta (7.5) | 43% | ⚠ Explotación activa | 7 may 2025 | SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read… |
| CVE-2024-36394 | Crítica (9.8) | 1.1% | — | 6 jun 2024 | SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
| CVE-2024-36393 | Crítica (9.8) | 0.42% | — | 6 jun 2024 | SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2024-27775 | Alta (7.2) | 0.58% | — | 28 mar 2024 | SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash |
| CVE-2023-47247 | Media (4.3) | 0.33% | — | 25 dic 2023 | In SysAid On-Premise before 23.3.34, there is an edge case in which an end user is able to delete a Knowledge Base article, aka bug 15102. |
| CVE-2023-33706 | Media (6.5) | 0.58% | — | 24 nov 2023 | SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp or a modified srID parameter to ShowMessage.jsp. |
| CVE-2023-47246 | Crítica (9.8) | 99% | ⚠ Explotación activa | 10 nov 2023 | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023. |
| CVE-2022-23166 | Crítica (9.8) | 1.1% | — | 12 may 2022 | Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame… |
| CVE-2022-23165 | Media (6.1) | 0.39% | — | 12 may 2022 | Sysaid – Sysaid 14.2.0 Reflected Cross-Site Scripting (XSS) - The parameter "helpPageName" used by the page "/help/treecontent.jsp" suffers from a Reflected Cross-Site Scripting vulnerability. For an attacker to exploit… |
| CVE-2022-22798 | Alta (8.8) | 0.61% | — | 12 may 2022 | Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest after that the system redirects him to the service portal or… |
| CVE-2022-22797 | Media (6.1) | 0.50% | — | 12 may 2022 | Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /CommunitySSORedirect.jsp?redirectURL=https://google.com. Unvalidated… |
| CVE-2022-22796 | Crítica (9.8) | 1.4% | — | 12 may 2022 | Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp… |
| CVE-2021-43973 | Alta (8.8) | 1.7% | — | 11 ene 2022 | An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful… |
| CVE-2021-43972 | Media (6.5) | 1.5% | — | 11 ene 2022 | An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an… |
| CVE-2021-43971 | Alta (8.8) | 1.7% | — | 11 ene 2022 | A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter. |
| CVE-2021-31862 | Media (6.1) | 4.0% | — | 29 oct 2021 | SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication. |
| CVE-2021-30486 | Alta (8.8) | 1.0% | — | 22 jul 2021 | SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group1), AssetManagementList.jsp (GET computerID or group1), or… |
| CVE-2021-30049 | Media (6.1) | 2.5% | — | 22 jul 2021 | SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI. |
| CVE-2015-3001 | Media (5) | 6.8% | — | 8 jun 2015 | SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of… |
| CVE-2015-3000 | Alta (7.8) | 8.0% | — | 8 jun 2015 | SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of nested entity references in an XML document to (1) /agententry, (2)… |
| CVE-2015-2999 | Media (6.5) | 1.8% | — | 8 jun 2015 | Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) groupFilter parameter in an AssetDetails report to /genericreport,… |
| CVE-2015-2998 | Media (5) | 26% | — | 8 jun 2015 | SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstrated by decrypting the database password in… |
| CVE-2015-2997 | Media (5) | 57% | — | 8 jun 2015 | SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which… |
| CVE-2015-2996 | Alta (8.5) | 87% | — | 8 jun 2015 | Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of… |
| CVE-2015-2995 | Media (6.8) | 34% | — | 8 jun 2015 | The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload and execute arbitrary files via a NULL byte after the extension, as demonstrated… |
| CVE-2015-2994 | Media (6.5) | 50% | — | 8 jun 2015 | Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp extension, then accessing it via a direct… |
| CVE-2015-2993 | Alta (7.5) | 55% | — | 8 jun 2015 | SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to… |
| CVE-2014-9436 | Media (5) | 6.9% | — | 2 ene 2015 | Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.