{"cveID":"CVE-2023-32315","vendorProject":"Ignite Realtime","product":"Openfire","vulnerabilityName":"Ignite Realtime Openfire Path Traversal Vulnerability","dateAdded":"2023-08-24","shortDescription":"Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-09-14","knownRansomwareCampaignUse":"Unknown","notes":"https://www.igniterealtime.org/downloads/#openfire;  https://nvd.nist.gov/vuln/detail/CVE-2023-32315","cwes":["CWE-22"],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-32315","technique":"T1202","technique_name_at_mapping":"Indirect Command Execution","mapping_type":"exploitation_technique","capability_group":"dir_traversal","comments":"CVE-2023-32315 is a path traversal bug in Openfire's administrative console that could be leveraged for remote code execution. Public reports have indicated that threat actors were exploiting this vulnerability to gain access to the Openfire plugins interface to create new admin console user accounts, install a malicious plugin, and gain access to a webshell.  ","references":["https://thehackernews.com/2023/08/thousands-of-unpatched-openfire-xmpp.html","https://www.bleepingcomputer.com/news/security/over-3-000-openfire-servers-vulnerable-to-takover-attacks/","https://surevine.com/resource-centre/openfire-cve-2023-32315-what-we-know"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-32315","technique":"T1087.002","technique_name_at_mapping":"Domain Account","mapping_type":"secondary_impact","capability_group":"dir_traversal","comments":"CVE-2023-32315 is a path traversal bug in Openfire's administrative console that could be leveraged for remote code execution. Public reports have indicated that threat actors were exploiting this vulnerability to gain access to the Openfire plugins interface to create new admin console user accounts, install a malicious plugin, and gain access to a webshell.  ","references":["https://thehackernews.com/2023/08/thousands-of-unpatched-openfire-xmpp.html","https://www.bleepingcomputer.com/news/security/over-3-000-openfire-servers-vulnerable-to-takover-attacks/","https://surevine.com/resource-centre/openfire-cve-2023-32315-what-we-know"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-32315","technique":"T1496","technique_name_at_mapping":"Resource Hijacking","mapping_type":"secondary_impact","capability_group":"dir_traversal","comments":"CVE-2023-32315 is a path traversal bug in Openfire's administrative console that could be leveraged for remote code execution. Public reports have indicated that threat actors were exploiting this vulnerability to gain access to the Openfire plugins interface to create new admin console user accounts, install a malicious plugin, and gain access to a webshell.  ","references":["https://thehackernews.com/2023/08/thousands-of-unpatched-openfire-xmpp.html","https://www.bleepingcomputer.com/news/security/over-3-000-openfire-servers-vulnerable-to-takover-attacks/","https://surevine.com/resource-centre/openfire-cve-2023-32315-what-we-know"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-32315","technique":"T1505.003","technique_name_at_mapping":"Web Shell","mapping_type":"primary_impact","capability_group":"dir_traversal","comments":"CVE-2023-32315 is a path traversal bug in Openfire's administrative console that could be leveraged for remote code execution. Public reports have indicated that threat actors were exploiting this vulnerability to gain access to the Openfire plugins interface to create new admin console user accounts, install a malicious plugin, and gain access to a webshell.  ","references":["https://thehackernews.com/2023/08/thousands-of-unpatched-openfire-xmpp.html","https://www.bleepingcomputer.com/news/security/over-3-000-openfire-servers-vulnerable-to-takover-attacks/","https://surevine.com/resource-centre/openfire-cve-2023-32315-what-we-know"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1087.002","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Domain Account","name_at_mapping":"Domain Account","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":21,"has_detection_strategy":true},{"id":"T1202","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Indirect Command Execution","name_at_mapping":"Indirect Command Execution","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":40,"has_detection_strategy":true},{"id":"T1496","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Resource Hijacking","name_at_mapping":"Resource Hijacking","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":13,"has_detection_strategy":true},{"id":"T1505.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Shell","name_at_mapping":"Web Shell","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":35,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}