Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
2017-04-21T18:59:00.317
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | tenable | appliance | 3.4.0 | Yes |
Application | tenable | appliance | 3.5.0 | Yes |
Application | tenable | appliance | 3.5.1 | Yes |
Application | tenable | appliance | 3.10.0 | Yes |
Application | tenable | appliance | 3.10.1 | Yes |
Application | tenable | appliance | 4.0.0 | Yes |
Application | tenable | appliance | 4.1.0 | Yes |
Application | tenable | appliance | 4.2.0 | Yes |
Application | tenable | appliance | 4.3.0 | Yes |
Application | tenable | appliance | 4.3.1 | Yes |
Application | tenable | appliance | 4.4.0 | Yes |