← Back

Sharefile Storage Zones Controller

sharefile_storage_zones_controller

Vendor: Progress • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Progress
1Sharefile Storage Zones Controller
Sep 2, 2026
Aug 17, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to...Show more
In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions.Show less
1Progress
1Sharefile Storage Zones Controller
Sep 2, 2026
Aug 17, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage...Show more
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.Show less
1Progress
1Sharefile Storage Zones Controller
Sep 2, 2026
Aug 17, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content t...Show more
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.Show less
1Progress
1Sharefile Storage Zones Controller
Sep 3, 2026
Jul 21, 2026
N/A· v4
8.7 HIGH· v3
N/A· v2
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write...Show more
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.Show less
1Progress
1Sharefile Storage Zones Controller
Jun 17, 2026
Apr 2, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
1Progress
1Sharefile Storage Zones Controller
Jun 17, 2026
Apr 2, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.