CVE-2014-5393

medium

Description

Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/95796

https://change.sos-berlin.com/browse/JS-1205

http://www.sos-berlin.com/modules/news/article.php?storyid=74

http://www.sos-berlin.com/modules/news/article.php?storyid=73

http://www.securityfocus.com/archive/1/533373/100/0/threaded

Details

Source: Mitre, NVD

Published: 2014-09-11

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00469