CVE-2014-9436: SysAid

Medium severity, CVSS 5.0. EPSS: 6.9% chance of exploitation in the next 30 days.

Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile.

Affected products

  • SysAid SysAid: up to and including 14.4

Published 2015-01-02. Last modified 2026-06-17.