PT-2014-4797 · Mcafee · Mcafee Asset Manager
Publicado
2014-03-23
·
Atualizado
2017-08-29
·
CVE-2014-2588
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
McAfee Asset Manager version 6.6
Description
A directory traversal issue exists, allowing remote authenticated users to read arbitrary files. This is achieved by using a .. (dot dot) in the
reportFileName parameter of the servlet/downloadReport endpoint.Recommendations
For McAfee Asset Manager version 6.6, restrict access to the servlet/downloadReport endpoint to minimize the risk of exploitation. Avoid using the
reportFileName parameter with untrusted input until the issue is resolved.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mcafee Asset Manager