Vulnary
← back to the feed
Critical· 9.8actively exploitedofficial fix available

CVE-2023-47246

SysAid On‑Premise before version 23.3.36 contains a critical path traversal flaw that lets attackers write files to the Tomcat webroot and then execute arbitrary code. The vulnerability was exploited in the wild in November 2023. Updating to 23.3.36 or later removes the flaw.

publishedNov 10, 2023
last modifiedJul 31, 2026
sourcesNVD · CISA-KEV
severity · cvss
9.8
critical · how bad it is
exploitation · epss
99%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 30, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

SysAid On‑Premise software, versions earlier than 23.3.36, used by organizations running the on‑premises solution.

02

Real-world impact

An attacker who can write to the Tomcat webroot can run arbitrary code on the server, potentially taking full control of the system.

03

Why this severity

The CVSS score of 9.8 reflects that the flaw is network‑exposed, requires no authentication, and gives attackers complete control over confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade SysAid On‑Premise to version 23.3.36 or later.
  2. 02Restart the Tomcat service to apply the update.

CISA KEV required action

05

Timeline

  1. Nov 10, 2023 · Nov 10, 2023
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Nov 13, 2023 · Nov 13, 2023
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  3. Dec 4, 2023 · Dec 4, 2023
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
  4. Jul 31, 2026 · 6d ago
    Advisory updated
    The NVD record was last revised.
  5. Jul 31, 2026 · 6d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →