CVE-2023-47246
SysAid On‑Premise before version 23.3.36 contains a critical path traversal flaw that lets attackers write files to the Tomcat webroot and then execute arbitrary code. The vulnerability was exploited in the wild in November 2023. Updating to 23.3.36 or later removes the flaw.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
SysAid On‑Premise software, versions earlier than 23.3.36, used by organizations running the on‑premises solution.
Real-world impact
An attacker who can write to the Tomcat webroot can run arbitrary code on the server, potentially taking full control of the system.
Why this severity
The CVSS score of 9.8 reflects that the flaw is network‑exposed, requires no authentication, and gives attackers complete control over confidentiality, integrity, and availability.
What to do about it
- 01Upgrade SysAid On‑Premise to version 23.3.36 or later.
- 02Restart the Tomcat service to apply the update.
CISA KEV required action
Timeline
- Nov 10, 2023 · Nov 10, 2023PublishedDisclosed and added to the National Vulnerability Database.
- Nov 13, 2023 · Nov 13, 2023Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Dec 4, 2023 · Dec 4, 2023CISA remediation deadlineFederal agencies are required to remediate by this date.
- Jul 31, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 31, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- documentation.sysaid.com/docs/latest-version-install…product
- documentation.sysaid.com/docs/on-premise-security-en…release notesvendor advisory
- sysaid.com/blog/service-desk/on-premis…exploitvendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource