
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in SquaredUp for SCOM 5.2.1.6654. The Download Log feature in System / Maintenance was susceptible to a local file inclusion vulnerability (when processing remote input in the log files downloaded by an authenticated administrator user), leading to the ability to read arbitrary files on the server filesystems (Vendor Advisory, NVD).
The vulnerability affects SquaredUp for SCOM version 5.2.1.6654 and earlier versions. It has been assigned a CVSS v3.1 Base Score of 4.9 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N (NVD).
The vulnerability allows authenticated administrator users to read arbitrary files on the server filesystems through the Download Log feature in System / Maintenance section. This could potentially expose sensitive system information and configurations (NVD).
Users running affected versions should upgrade to version 5.3.1 or later. This applies to SCOM Edition, Azure Edition, and Community Edition installations (Vendor Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."