CVE-2024-58298

CVSS

No CVSS.

C

ompuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicious JSP files through a path traversal in the file upload form. Attackers can exploit the 'fileName' parameter to upload a web shell and execute arbitrary commands by sending POST requests to the uploaded JSP endpoint.

Configurations

No configuration.

History

12 Dec 2025, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 22:15

Updated : 2025-12-12 15:17


NVD link : CVE-2024-58298

Mitre link : CVE-2024-58298

CVE.ORG link : CVE-2024-58298


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type