Vulnerability record · CVE-2015-2997 · published 8 June 2015
CVE-2015-2997: SysAid Help Desk path disclosure via getAgentLogFile accountid
Sysaid · Sysaid
SysAid Help Desk before 15.2 exposes sensitive information through the getAgentLogFile endpoint when an invalid accountid value, such as a large directory traversal sequence, is supplied. The error message returned reveals the installation path, giving attackers a foothold for further targeting. The flaw is an information exposure issue (CWE-200) rated MEDIUM under CVSS 2.0.
Description
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which reveals the installation path in an error message.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityThe flaw only discloses the installation path, but it is remotely reachable without authentication and has public exploit material plus a very high EPSS score.
What it is
SysAid Help Desk before 15.2 exposes sensitive information through the getAgentLogFile endpoint when an invalid accountid value, such as a large directory traversal sequence, is supplied. The error message returned reveals the installation path, giving attackers a foothold for further targeting. The flaw is an information exposure issue (CWE-200) rated MEDIUM under CVSS 2.0.
Impact
An unauthenticated remote attacker learns the server's installation path from the error response. That path disclosure alone does not grant code execution but aids reconnaissance for follow-on attacks.
Attack surface
Reachable over the network through the getAgentLogFile endpoint with a crafted accountid parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
No CISA KEV listing, but EPSS is 0.57204 (99th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade SysAid Help Desk to version 15.2 or later, which the vendor advisory identifies as the fixed release.
- Validate and sanitize the accountid parameter, rejecting traversal sequences and non-numeric values.
- Suppress detailed error messages and installation paths from responses returned to clients.
- Restrict network access to the SysAid Help Desk interface to trusted users and networks.
- Monitor vendor advisories for any further fixes affecting the getAgentLogFile endpoint.
Detection
- Search web or application logs for requests to getAgentLogFile with accountid values containing traversal sequences such as ../ or long dot-slash strings.
- Alert on error responses that include filesystem paths or installation directories.
- Baseline normal accountid values and flag outliers or unusually long parameter lengths.
- Review SysAid access logs for unauthenticated requests to the getAgentLogFile endpoint from unexpected sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-2997 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-2997), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.