← Vulnerability feed

Vulnerability record · CVE-2023-47246 · published 10 November 2023

CVE-2023-47246: SysAid On-Premise path traversal leads to remote code execution

Sysaid · Sysaid

SysAid On-Premise before 23.3.36 contains a path traversal flaw that lets an unauthenticated attacker write a file into the Tomcat webroot, which then executes as code. It was exploited in the wild in November 2023 and is listed in CISA's KEV catalog with known ransomware campaign use, so internet-facing instances are at immediate risk.

9.8 CVSS 3.1 Critical CISA KEV since 13 Nov 2023 Known ransomware use EPSS 99% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 2 tagged exploit
31 Jul 2026Last modified by NVD

Description

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution, active in-the-wild exploitation, KEV listing with ransomware use, and near-maximum EPSS score.

What it is

SysAid On-Premise before 23.3.36 contains a path traversal flaw that lets an unauthenticated attacker write a file into the Tomcat webroot, which then executes as code. It was exploited in the wild in November 2023 and is listed in CISA's KEV catalog with known ransomware campaign use, so internet-facing instances are at immediate risk.

Impact

An attacker gains remote code execution on the SysAid server, allowing full compromise of the host and any data or credentials it holds. Given the KEV ransomware association, follow-on ransomware deployment is a realistic outcome.

Attack surface

Reachable over the network via the SysAid web interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed On-Premise instance below 23.3.36 is a candidate target.

Exploitation

Exploited in the wild as of November 2023 and added to CISA KEV on 2023-11-13 with a 2023-12-04 remediation due date; EPSS 30-day probability is 0.98851 (99.9th percentile). Vendor and government references are tagged Exploit and US Government Resource.

What to do

  • Upgrade SysAid On-Premise to 23.3.36 or later immediately; this is the only complete fix.
  • If patching cannot be done at once, remove the instance from internet exposure and apply the vendor's documented security enhancements.
  • Follow the vendor's post-exploitation guidance to check for and remove any files or web shells written to the Tomcat webroot.
  • Rotate credentials and secrets stored or processed by the SysAid server, and review it for signs of lateral movement.
  • Treat the host as potentially compromised if it was exposed before patching, and rebuild if compromise is confirmed.

Detection

  • Monitor the Tomcat webroot and SysAid application directories for newly created or modified files, especially unexpected scripts or archives.
  • Alert on suspicious child processes spawned by the Tomcat/SysAid service, such as command shells or scripting interpreters.
  • Review web server and SysAid logs for path traversal patterns (../ sequences) and anomalous POST requests around the exploitation window.
  • Hunt for outbound connections or tooling consistent with ransomware staging on hosts running SysAid On-Premise.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-47246 to the Known Exploited Vulnerabilities catalog on 13 November 2023 as "SysAid Server Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 4 December 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-47246 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed7.5CVE-2025-2775SysAid On-Prem unauthenticated XXE in Checkin processingSysAid On-Prem versions up to 23.3.40 process Checkin XML without restricting external entities, so an unauthenticated attacker can supply a crafted …KEVEPSS 43%analysed9.8CVE-2025-2777SysAid On-Prem unauthenticated XXE in lshw processingSysAid On-Prem versions up to 23.3.40 process lshw data through an XML parser that resolves external entities, so an unauthenticated request can trig…EPSS 72%analysed9.8CVE-2024-36393Sysaid sql injection vulnerabilitySysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')EPSS 0.42%9.8CVE-2024-36394Sysaid os command injection vulnerabilitySysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.1%9.8CVE-2022-23166Sysaid path traversal vulnerabilitySysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" …EPSS 1.1%9.8CVE-2022-22796Sysaid improper authentication vulnerabilitySysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, t…EPSS 1.4%8.8CVE-2022-22798Sysaid vulnerabilitySysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest a…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2023-47246), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.