important · Edge devices
Unauthenticated requests to Check Point's management web service can execute scripts or load Java classes.
Affects
Check Point Security Management, Log Server and Multi-Domain management products that administer enterprise security gateways.
Today's scope update pins the path to the management service on TCP port 19009: a pre-authentication traversal reaches attacker-directed script execution and arbitrary Java class loading. Check Point has published a fix.