An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Apr 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kovai
Kovai biztalk360 |
|
| CPEs | cpe:2.3:a:kovai:biztalk360:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kovai
Kovai biztalk360 |
|
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Biztalk360
Biztalk360 biztalk360 |
|
| Vendors & Products |
Biztalk360
Biztalk360 biztalk360 |
Fri, 03 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Allowing Super User File Read in Biztalk360 | |
| Weaknesses | CWE-22 |
Fri, 03 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Biztalk360 through 11.5. because of mishandling of user-provided input in a path to be read by the server, a Super User attacker is able to read files on the system and/or coerce an authentication from the service, aka Directory Traversal. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T14:39:38.152Z
Reserved: 2025-09-19T00:00:00.000Z
Link: CVE-2025-59709
No data.
Status : Analyzed
Published: 2026-04-03T15:16:03.817
Modified: 2026-04-09T00:57:10.453
Link: CVE-2025-59709
No data.
OpenCVE Enrichment
Updated: 2026-04-06T21:23:15Z
Weaknesses