Cisco HyperFlex HX... CVE-2021-1497 CVE-2021-1498

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# CVE-2021-1497 and/or CVE-2021-1498 Command injection in the `/storfs-asup` endpoint’s `token` and `mode` parameters. ## Patch ``` --- unpatched/web.xml2021-05-17 19:06:17.000000000 -0500 +++ patched/web.xml2021-05-17 19:06:23.000000000 -0500 @@ -69,17 +69,6 @@ </servlet-mapping> <servlet> -<servlet-name>Springpath Storfs ASUP</servlet-name> -<servlet-class>com.storvisor.sysmgmt.service.StorfsAsup</servlet-class> -<load-on-startup>1</load-on-startup> -</servlet> - -<servlet-mapping> -<servlet-name>Springpath Storfs ASUP</servlet-name> -<url-pattern>/storfs-asup/*</url-pattern> -</servlet-mapping> - -<servlet> <servlet-name>Springpath Upgrade Image Upload Service</servlet-name> <servlet-class>com.storvisor.sysmgmt.service.StorvisorFileUploader</servlet-class> </servlet> ``` ## Vulnerability ``` protected void processRequest(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { String action = request.getParameter("action"); if (action ==...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息