An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when installed for non-root operations (scanning), can be forced to copy files from the filesystem to other locations via Symbolic Link Following.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Eda_agent | Eracent | * | 10.2.26 (including) |
| Epa_agent | Eracent | * | 10.2.26 (including) |
| Epm_agent | Eracent | * | 10.2.26 (including) |
| Eua_agent | Eracent | * | 10.2.26 (including) |
| Flw_agent | Eracent | * | 10.2.26 (including) |
| Sum_agent | Eracent | * | 10.2.26 (including) |