IT

Tracker / CVE-2019-17445

CVE-2019-17445

Medium 5.5

An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.

Affected products and versions

eracent eda_agent · … → 10.2.26
eracent epa_agent · … → 10.2.26
eracent epm_agent · … → 10.2.26
eracent eua_agent · … → 10.2.26
eracent flw_agent · … → 10.2.26
eracent sum_agent · … → 10.2.26

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References