Show plain JSON{"containers": {"cna": {"affected": [{"product": "Orca HCM", "vendor": "Learningdigital.com, Inc.", "versions": [{"lessThanOrEqual": "10.0", "status": "affected", "version": "unspecified", "versionType": "custom"}]}], "datePublic": "2021-07-19T00:00:00", "descriptions": [{"lang": "en", "value": "The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users\u2019 privileges."}], "metrics": [{"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 4.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "version": "3.1"}}], "problemTypes": [{"descriptions": [{"cweId": "CWE-22", "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"dateUpdated": "2021-07-19T11:55:47", "orgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e", "shortName": "twcert"}, "references": [{"tags": ["x_refsource_MISC"], "url": "https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25"}, {"tags": ["x_refsource_MISC"], "url": "https://www.twcert.org.tw/tw/cp-132-4928-7e87b-1.html"}], "solutions": [{"lang": "en", "value": "Update Orca HCM to version 10.9"}], "source": {"advisory": "TVN-202107009", "discovery": "EXTERNAL"}, "title": "Learningdigital.com, Inc. Orca HCM - Path Traversal-2", "x_generator": {"engine": "Vulnogram 0.0.9"}, "x_legacyV4Record": {"CVE_data_meta": {"AKA": "TWCERT/CC", "ASSIGNER": "cve@cert.org.tw", "DATE_PUBLIC": "2021-07-19T11:36:00.000Z", "ID": "CVE-2021-35968", "STATE": "PUBLIC", "TITLE": "Learningdigital.com, Inc. Orca HCM - Path Traversal-2"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "Orca HCM", "version": {"version_data": [{"version_affected": "<=", "version_value": "10.0"}]}}]}, "vendor_name": "Learningdigital.com, Inc."}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote attackers can access the system directory thru Path Traversal with users\u2019 privileges."}]}, "generator": {"engine": "Vulnogram 0.0.9"}, "impact": {"cvss": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 4.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "version": "3.1"}}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"}]}]}, "references": {"reference_data": [{"name": "https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25", "refsource": "MISC", "url": "https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25"}, {"name": "https://www.twcert.org.tw/tw/cp-132-4928-7e87b-1.html", "refsource": "MISC", "url": "https://www.twcert.org.tw/tw/cp-132-4928-7e87b-1.html"}]}, "solution": [{"lang": "en", "value": "Update Orca HCM to version 10.9"}], "source": {"advisory": "TVN-202107009", "discovery": "EXTERNAL"}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-04T00:47:42.584Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://www.chtsecurity.com/news/ba7b3ae7-14f3-4970-b3f6-4d97d8c7ea25"}, {"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://www.twcert.org.tw/tw/cp-132-4928-7e87b-1.html"}]}]}, "cveMetadata": {"assignerOrgId": "cded6c7f-6ce5-4948-8f87-aa7a3bbb6b0e", "assignerShortName": "twcert", "cveId": "CVE-2021-35968", "datePublished": "2021-07-19T11:55:47.851205Z", "dateReserved": "2021-06-30T00:00:00", "dateUpdated": "2024-09-17T01:01:11.960Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}