External risk intelligence

LiveBOS Arbitrary File Upload Vulnerability Allows Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2024-13981

The vulnerability resides in a web-accessible endpoint (UploadFile.do) within a business middleware platform. Such middleware suites are frequently deployed as web-facing applications or centralized portals to facilitate business operations, making the file upload functionality reachable from the network in many common deployment patterns.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in LiveBOS, a business middleware platform, allowing unauthenticated attackers to upload files to unauthorized locations. This could potentially lead to remote code execution and full system compromise. The vulnerability is presumed to affect versions released before August 2024, with newer versions offering a fix, though the specific affected range is not precisely defined.

  • Allows unauthorized file uploads.
  • Could lead to remote system compromise.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An unauthenticated remote attacker can exploit a file upload vulnerability in LiveBOS's UploadFile.do endpoint. By crafting a filename to traverse directories, an attacker can upload arbitrary files outside the intended storage location. This could allow for remote code execution and full server compromise. Evidence of exploitation was first observed in late August 2024, and the vulnerability is presumed to affect versions released before August 2024.

  • No authentication required.
  • Upload crafted files via filename.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could impact the integrity and availability of the LiveBOS Server component. By uploading specially crafted files, an attacker could potentially execute arbitrary code on the server, leading to a complete system compromise. This risk is present when the UploadFile.do;.js.jsp endpoint is accessible.

  • Server code execution.
  • Unauthenticated remote file upload.
  • Full system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The LiveBOS middleware platform is likely managed by infrastructure or platform teams, with application owners responsible for specific business functions built upon it. The first practical step is to inventory all LiveBOS deployments, assess their network exposure and business criticality, and identify the accountable owners for each instance to prioritize remediation.

  • Infrastructure or Platform Teams own the issue.
  • Verify LiveBOS network exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is LiveBOS and what is it used for?

LiveBOS is an object-oriented business architecture middleware suite created by Apex Software Co., Ltd. It serves as a backend platform that organizations use to build, manage, and host complex business applications, often acting as a central server component for enterprise operations.

What does CVE-2024-13981 mean for system security?

This vulnerability involves two common software weaknesses: improper restriction of pathnames (CWE-22) and unrestricted file uploads (CWE-434). It allows an attacker to bypass directory restrictions when uploading files, which can lead to remote code execution and full system compromise.

How can an attacker trigger this file upload vulnerability?

An attacker triggers this by interacting with the UploadFile.do endpoint. By using path traversal techniques within the filename parameter, they can force the server to save files in unauthorized directories. Accessing the endpoint itself is the primary requirement, meaning the vulnerability is not triggered by standard, authorized file operations.

Is my instance of LiveBOS at risk?

Halo Surface Signal indicates that because this flaw exists in a web-accessible middleware endpoint, any instance exposed to the network is at higher risk. You should determine if your deployment is internet-facing or reachable from untrusted network segments, as this increases the likelihood of unauthorized access.

How should I respond to this threat?

Begin by inventorying all LiveBOS installations within your environment to confirm their current version. Since the issue affects builds prior to August 2024, prioritize updating any identified instances to the latest available version provided by the vendor to remediate the vulnerability.

References