CVE-2024-13981

CVSS

No CVSS.

L

iveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerability in its UploadFile.do;.js.jsp endpoint. This flaw affects the LiveBOS Server component and allows unauthenticated remote attackers to upload crafted files outside the intended directory structure via path traversal in the filename parameter. Successful exploitation may lead to remote code execution on the server, enabling full system compromise. The vulnerability is presumed to affect builds released prior to August 2024 and is said to be remediated in newer versions of the product, though the exact affected range remains undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-08-23 UTC.

Configurations

No configuration.

History

29 Aug 2025, 16:24

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-27 22:15

Updated : 2025-08-29 16:24


NVD link : CVE-2024-13981

Mitre link : CVE-2024-13981

CVE.ORG link : CVE-2024-13981


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-434

Unrestricted Upload of File with Dangerous Type