Skip to content
COOEY

EXPOSURES › CVE-2022-36537

CVE-2022-36537

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-02-27 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-36537 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 ransomwareexploited-in-wildunpatched

ZK Framework AuUploader servlets allow attackers to read arbitrary files in the web context, impacting products like ConnectWise R1Soft Server Backup Manager.

This file-read vulnerability enables attackers to exfiltrate sensitive data from systems using the ZK Framework, including backup managers. DIB organizations must verify their software supply chain for unpatched, actively exploited flaws like this one, which is now KEV and ransomware-linked. Immediate patching and supply-chain risk assessments are required to prevent data breaches and compliance failures.

Shame score — An open-source framework shipped with an unpatched, actively exploited vulnerability that attackers used for ransomware, demonstrating severe negligence in maintaining critical infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java framework. This vulnerability can impact multiple products, including but not limited to ConnectWise R1Soft Server Backup Manager.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.