On this page
Atomicorp WAF Rule 347019
Rule Summary
- Rule ID: 347019
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Suspicious path recursion denied
- Observed CWEs: CWE-22 (17), CWE-28 (1), CWE-94 (1), CWE-200 (2), CWE-502 (1), CWE-552 (2)
- Revision: 15
- Rule severity: Critical (2)
- Phase: 1 (request headers)
- Request surfaces: Raw request URI, Request filename, Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Suspicious path recursion denied” in the raw request URI, request filename, request arguments, JSON request data, SOAP request data. It evaluates during the request headers phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2020-10189 | ManageEngine Desktop Central Java Deserialization | manageengine desktop central | 9.8 (v3.1) | Critical |
| CVE-2023-39143 | PaperCut < 22.1.3 - Path Traversal | papercut mf | 9.8 (v3.1) | Critical |
| CVE-2024-8752 | WebIQ 2.15.9 - Directory Traversal | webiq | 9.3 (v4.0) | Critical |
| CVE-2024-6911 | PerkinElmer ProcessPlus <= 1.11.6507.0 - Local File Inclusion | processplus | 8.7 (v4.0) | High |
| CVE-2025-61666 | Traccar(Windows) 6.1- 6.8.1 - Local File Inclusion | traccar | 8.7 (v4.0) | High |
| CVE-2024-21136 | Oracle Retail Xstore Suite - Pre-authenticated Path Traversal | retail xstore office | 8.6 (v3.1) | High |
| CVE-2025-6204 | DELMIA Apriso - Command Injection | delmia apriso | 8.0 (v3.1) | High |
| CVE-2017-11512 | ManageEngine ServiceDesk 9.3.9328 - Arbitrary File Retrieval | servicedesk | 7.5 (v3.0) | High |
| CVE-2018-7719 | Acrolinx Server <5.2.5 - Local File Inclusion | acrolinx server | 7.5 (v3.0) | High |
| CVE-2019-12593 | IceWarp Mail Server <=10.4.4 - Local File Inclusion | mail server | 7.5 (v3.0) | High |
| CVE-2021-34805 | FAUST iServer 9.0.018.018.4 - Local File Inclusion | faust iserver | 7.5 (v3.1) | High |
| CVE-2022-26233 | Barco Control Room Management Suite <=2.9 Build 0275 - Local File Inclusion | control room management suite | 7.5 (v3.1) | High |
| CVE-2022-27043 | Yearning - Directory Traversal | yearning | 7.5 (v3.1) | High |
| CVE-2023-31059 | Repetier Server - Directory Traversal | repetier-server | 7.5 (v3.1) | High |
| CVE-2023-34843 | Traggo Server - Local File Inclusion | traggo | 7.5 (v3.1) | High |
| CVE-2023-39026 | FileMage Gateway - Directory Traversal | Windows | 7.5 (v3.1) | High |
| CVE-2024-28995 | SolarWinds Serv-U - Directory Traversal | serv-u | 7.5 (v3.1) | High |
| CVE-2024-46938 | Sitecore Experience Platform <= 10.4 - Arbitrary File Read | experience commerce | 7.5 (v3.1) | High |
| CVE-2025-11371 | Gladinet CentreStack & TrioFox - Local File Inclusion | centrestack | 7.5 (v3.1) | High |
| CVE-2021-21402 | Jellyfin <10.7.0 - Local File Inclusion | jellyfin | 6.5 (v3.1) | Medium |
| CVE-2012-4940 | Axigen Mail Server Filename Directory Traversal | axigen free mail server | 6.4 (v2.0) | Medium |
| CVE-2018-16133 | Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal | cybrohttpserver | 5.3 (v3.0) | Medium |
| CVE-2019-18393 | Ignite Realtime Openfire <4.42 - Local File Inclusion | openfire | 5.3 (v3.1) | Medium |
| CVE-2023-2059 | DedeCMS 5.7.87 - Directory Traversal | dedecms | 5.3 (v3.1) | Medium |
| CVE-2019-2588 | Oracle Business Intelligence - Path Traversal | business intelligence publisher | 4.9 (v3.0) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.