| [Japanese] | 
| JVNDB-2023-000121 | 
| RakRak Document Plus vulnerable to path traversal | 
|
| 
 
RakRak Document Plus provided by Sumitomo Electric Information Systems Co., Ltd. contains a path traversal vulnerability (CWE-22).
 Asato Masamu of GMO Cybersecurity by Ierae, Inc. reported this vulnerability to IPA.
 JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
 | 
|
| 
 
  CVSS V3 Severity:Base Metrics 6.8 (Medium) [IPA Score]
 
    Attack Vector: Adjacent NetworkAttack Complexity: LowPrivileges Required: LowUser Interaction: NoneScope: UnchangedConfidentiality Impact: HighIntegrity Impact: LowAvailability Impact: Low 
  CVSS V2 Severity:Base Metrics 6.7 (Medium) [IPA Score]
 
    Access Vector: Adjacent NetworkAccess Complexity: LowAuthentication: Single InstanceConfidentiality Impact: CompleteIntegrity Impact: PartialAvailability Impact: Partial 
  
 | 
|
| 
 
	
 | 
| 
 
	Sumitomo Electric Information Systems Co., Ltd.
	
		RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 | 
| 
 
	The developer states that RakRak Document Plus Ver.6.1.1.3a is not affected by this vulnerability.
 | 
|
| 
 
Arbitrary files on the server may be obtained or deleted by a user of the product with specific privileges.
 | 
|
| 
 
[Update the Software]Update the software to the latest version according to the information provided by the developer.
 The developer released "Rakuraku Document Plus Ver.6.5.0.0" on January 17, 2024, which contains a fix for this vulnerability.
 
 [Apply the Patch]
 The developer released patches for the affected versions.
 
 [Apply the Workaround]
 The developer also recommends users apply the workaround.
 
 For more information, refer to the information provided by the developer.
 | 
|
| 
 
	Sumitomo Electric Information Systems Co., Ltd.
	
 | 
|
| 
 
	Path Traversal(CWE-22) [IPA Evaluation] | 
|
| 
 
	CVE-2023-49108  | 
|
| 
 
	JVN : JVN#46895889 National Vulnerability Database (NVD) : CVE-2023-49108  | 
|
| 
 
	[2023/12/04]Web page was published
[2024/01/24]Solution was modified
 
 |