LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-36537: ZK Framework AuUploader Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 27, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 20, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-36537 to its Known Exploited Vulnerabilities catalog on Feb 27, 2023, with a federal patch deadline of Mar 20, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context. The ZK Framework is an open-source Java…

CVE-2022-36537 is an unspecified vulnerability in the AuUploader component of the ZK Framework, an open-source Java framework used to build web applications. It can allow an attacker to retrieve the content of a file located in the web context. Because the ZK Framework is embedded in multiple products, including ConnectWise R1Soft Server Backup Manager and others, the issue can surface across different enterprise systems. CISA notes known ransomware use of this vulnerability, so unpatched instances present a clear risk of unauthorized file access that can support further compromise.

Defenders should treat any deployment of ZK Framework AuUploader servlets as potentially exposed until the vendor-supplied update is confirmed and applied. Specifics on exact product versions and configurations must be verified against the relevant vendor advisory.

How it works

The weakness is classified as CWE-441 (Unintended Proxy or Intermediary). In this case the AuUploader servlets act as an intermediary that can be abused to retrieve file content from the web context. An attacker who can reach the vulnerable servlet can cause it to return the contents of a file that should not be directly accessible, effectively turning the component into an unintended proxy for local file disclosure.

No further exploit mechanics are provided in public summaries. The practical impact is unauthorized reading of files within the application's web context, which may include configuration data, credentials, or other sensitive material depending on what resides there. Confirm the precise attack surface and any required preconditions against the vendor advisory for the product in use.

Am I affected? How to find it in your systems

ZK Framework is commonly found in Java-based web applications and can be packaged inside commercial products such as ConnectWise R1Soft Server Backup Manager. Inventory efforts should therefore cover both custom Java applications that declare a dependency on ZK Framework and any third-party products known to embed it.

Telemetry signs of exploitation are not detailed in the available summary. Monitor web server and application logs for unusual requests targeting AuUploader endpoints or for unexpected file-read activity originating from the application process. Any anomalous access to files under the web context should be investigated promptly.

How to remediate

The primary remediation is to apply the updates provided by the vendor, as directed by CISA. Obtain the patched release or security update for every product that incorporates the vulnerable ZK Framework AuUploader component and deploy it according to the vendor's instructions.

Once the update is applied, review and harden the surrounding configuration: restrict the web context so that only necessary files are present, enforce least-privilege permissions on the application process, and ensure that any file-upload or servlet functionality is limited to authenticated and authorized users.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls appropriate to this class of file-disclosure vulnerability.

These measures lower risk but do not eliminate it; schedule the official update as soon as operationally possible.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to data breaches. If systems running the vulnerable AuUploader component were internet-facing or otherwise reachable by untrusted parties, assume that files within the web context may have been retrieved. Review access logs, investigate for signs of follow-on activity, and follow your incident-response procedures. As an additional check, you can run a free exposure scan of your email addresses against known breach data to determine whether related credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZK Framework · AuUploader
WeaknessCWE-441
Added to CISA KEVFeb 27, 2023
Federal patch deadlineMar 20, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities