Aternity SteelCentral AppInternals是美国Aternity公司的一个监控现代自动化解决方案。提供应用程序性能监控 (APM) 和诊断。 Aternity SteelCentral AppInternals 存在安全漏洞,该漏洞允许攻击者制作自己的恶意负载来触发 XSS 漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Aternity | SteelCentral AppInternals Dynamic Sampling Agent | 10.x | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-42786 | 9.8 CRITICAL | Remote Code Execution at AgentControllerServlet |
| CVE-2021-42854 | 9.8 CRITICAL | Directory Traversal Read/Write/Delete at PluginServlet |
| CVE-2021-42787 | 9.4 CRITICAL | Directory Traversal Write/Delete/Partial Read at AgentConfigurationServlet |
| CVE-2021-42853 | 9.1 CRITICAL | Directory Traversal Delete/Read at AgentDiagnosticServlet |
| CVE-2021-42855 | 7.8 HIGH | Local privilege escalation due to misconfigured write permission on .debug_command.config |
| CVE-2021-42857 | 5.3 MEDIUM | Directory Traversal Partial Write at AgentDaServlet |
No comments yet