sk183137 - Mobile Access File Share applications are vulnerable to directory traversal attacks

Mobile Access File Share applications are vulnerable to directory traversal attacks

Please read this important update from Check Point.

Security Alert:

Symptoms

Additionally, an authenticated, malicious end-user may create arbitrary files with 'nobody' permissions on the Mobile Access gateway's '/tmp' folder.

Access to file contents does not seem possible via the attack described above, as the vulnerable API is capable of directory listing and file upload only.

Solution

This problem was fixed.  The fix is included in:

Article Properties