Vulnerability record · CVE-2023-47246 · published 10 November 2023
CVE-2023-47246: SysAid On-Premise path traversal leads to remote code execution
Sysaid · Sysaid
SysAid On-Premise before 23.3.36 contains a path traversal flaw that lets an unauthenticated attacker write a file into the Tomcat webroot, which then executes as code. It was exploited in the wild in November 2023 and is listed in CISA's KEV catalog with known ransomware campaign use, so internet-facing instances are at immediate risk.
Description
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution, active in-the-wild exploitation, KEV listing with ransomware use, and near-maximum EPSS score.
What it is
SysAid On-Premise before 23.3.36 contains a path traversal flaw that lets an unauthenticated attacker write a file into the Tomcat webroot, which then executes as code. It was exploited in the wild in November 2023 and is listed in CISA's KEV catalog with known ransomware campaign use, so internet-facing instances are at immediate risk.
Impact
An attacker gains remote code execution on the SysAid server, allowing full compromise of the host and any data or credentials it holds. Given the KEV ransomware association, follow-on ransomware deployment is a realistic outcome.
Attack surface
Reachable over the network via the SysAid web interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed On-Premise instance below 23.3.36 is a candidate target.
Exploitation
Exploited in the wild as of November 2023 and added to CISA KEV on 2023-11-13 with a 2023-12-04 remediation due date; EPSS 30-day probability is 0.98851 (99.9th percentile). Vendor and government references are tagged Exploit and US Government Resource.
What to do
- Upgrade SysAid On-Premise to 23.3.36 or later immediately; this is the only complete fix.
- If patching cannot be done at once, remove the instance from internet exposure and apply the vendor's documented security enhancements.
- Follow the vendor's post-exploitation guidance to check for and remove any files or web shells written to the Tomcat webroot.
- Rotate credentials and secrets stored or processed by the SysAid server, and review it for signs of lateral movement.
- Treat the host as potentially compromised if it was exposed before patching, and rebuild if compromise is confirmed.
Detection
- Monitor the Tomcat webroot and SysAid application directories for newly created or modified files, especially unexpected scripts or archives.
- Alert on suspicious child processes spawned by the Tomcat/SysAid service, such as command shells or scripting interpreters.
- Review web server and SysAid logs for path traversal patterns (../ sequences) and anomalous POST requests around the exploitation window.
- Hunt for outbound connections or tooling consistent with ransomware staging on hosts running SysAid On-Premise.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-47246 to the Known Exploited Vulnerabilities catalog on 13 November 2023 as "SysAid Server Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 4 December 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://documentation.sysaid.com/docs/latest-version-installation-files | Product |
| https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023 | Release NotesVendor Advisory |
| https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification | ExploitVendor Advisory |
| https://documentation.sysaid.com/docs/latest-version-installation-files | Product |
| https://documentation.sysaid.com/docs/on-premise-security-enhancements-2023 | Release NotesVendor Advisory |
| https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification | ExploitVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-47246 | US Government Resource |
Track CVE-2023-47246 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-47246), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.