On this page

Atomicorp WAF Rule 347019

Rule Summary

  • Rule ID: 347019
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Suspicious path recursion denied
  • Observed CWEs: CWE-22 (17), CWE-28 (1), CWE-94 (1), CWE-200 (2), CWE-502 (1), CWE-552 (2)
  • Revision: 15
  • Rule severity: Critical (2)
  • Phase: 1 (request headers)
  • Request surfaces: Raw request URI, Request filename, Request arguments, JSON request data, SOAP request data
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects behavior identified by its current alert as “Suspicious path recursion denied” in the raw request URI, request filename, request arguments, JSON request data, SOAP request data. It evaluates during the request headers phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2020-10189ManageEngine Desktop Central Java Deserializationmanageengine desktop central9.8 (v3.1)Critical
CVE-2023-39143PaperCut < 22.1.3 - Path Traversalpapercut mf9.8 (v3.1)Critical
CVE-2024-8752WebIQ 2.15.9 - Directory Traversalwebiq9.3 (v4.0)Critical
CVE-2024-6911PerkinElmer ProcessPlus <= 1.11.6507.0 - Local File Inclusionprocessplus8.7 (v4.0)High
CVE-2025-61666Traccar(Windows) 6.1- 6.8.1 - Local File Inclusiontraccar8.7 (v4.0)High
CVE-2024-21136Oracle Retail Xstore Suite - Pre-authenticated Path Traversalretail xstore office8.6 (v3.1)High
CVE-2025-6204DELMIA Apriso - Command Injectiondelmia apriso8.0 (v3.1)High
CVE-2017-11512ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrievalservicedesk7.5 (v3.0)High
CVE-2018-7719Acrolinx Server <5.2.5 - Local File Inclusionacrolinx server7.5 (v3.0)High
CVE-2019-12593IceWarp Mail Server <=10.4.4 - Local File Inclusionmail server7.5 (v3.0)High
CVE-2021-34805FAUST iServer 9.0.018.018.4 - Local File Inclusionfaust iserver7.5 (v3.1)High
CVE-2022-26233Barco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusioncontrol room management suite7.5 (v3.1)High
CVE-2022-27043Yearning - Directory Traversalyearning7.5 (v3.1)High
CVE-2023-31059Repetier Server - Directory Traversalrepetier-server7.5 (v3.1)High
CVE-2023-34843Traggo Server - Local File Inclusiontraggo7.5 (v3.1)High
CVE-2023-39026FileMage Gateway - Directory TraversalWindows7.5 (v3.1)High
CVE-2024-28995SolarWinds Serv-U - Directory Traversalserv-u7.5 (v3.1)High
CVE-2024-46938Sitecore Experience Platform <= 10.4 - Arbitrary File Readexperience commerce7.5 (v3.1)High
CVE-2025-11371Gladinet CentreStack & TrioFox - Local File Inclusioncentrestack7.5 (v3.1)High
CVE-2021-21402Jellyfin <10.7.0 - Local File Inclusionjellyfin6.5 (v3.1)Medium
CVE-2012-4940Axigen Mail Server Filename Directory Traversalaxigen free mail server6.4 (v2.0)Medium
CVE-2018-16133Cybrotech CyBroHttpServer 1.0.3 - Directory Traversalcybrohttpserver5.3 (v3.0)Medium
CVE-2019-18393Ignite Realtime Openfire <4.42 - Local File Inclusionopenfire5.3 (v3.1)Medium
CVE-2023-2059DedeCMS 5.7.87 - Directory Traversaldedecms5.3 (v3.1)Medium
CVE-2019-2588Oracle Business Intelligence - Path Traversalbusiness intelligence publisher4.9 (v3.0)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2023-39143 , CVE-2024-8752 , CVE-2025-61666 , CVE-2017-11512 , CVE-2018-7719 , CVE-2019-12593 , CVE-2021-34805 , CVE-2022-26233 , CVE-2022-27043 , CVE-2023-31059 , CVE-2023-34843 , CVE-2023-39026 , CVE-2024-28995 , CVE-2021-21402 , CVE-2012-4940 , CVE-2018-16133 , CVE-2019-18393
CWE-28CVE-2023-2059
CWE-94CVE-2025-6204
CWE-200CVE-2024-21136 , CVE-2024-46938
CWE-502CVE-2020-10189
CWE-552CVE-2024-6911 , CVE-2025-11371