PT-2017-16369 · Micro Focus · Open Enterprise Server

Publicado

2017-01-23

·

Atualizado

2020-02-24

·

CVE-2017-5182

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open Enterprise Server (OES) versions prior to OES2015 SP1 Maintenance Update 11080 Open Enterprise Server (OES) versions prior to OES2015 Maintenance Update 11079 Open Enterprise Server (OES) versions prior to OES11 SP3 Maintenance Update 11078 Open Enterprise Server (OES) versions prior to OES11 SP2 Maintenance Update 11077
Description The issue allows unauthenticated remote attackers to read any arbitrary file via a specially crafted URL, enabling complete directory traversal and total information disclosure.
Recommendations For OES2015 SP1, apply Maintenance Update 11080 to resolve the issue. For OES2015, apply Maintenance Update 11079 to resolve the issue. For OES11 SP3, apply Maintenance Update 11078 to resolve the issue. For OES11 SP2, apply Maintenance Update 11077 to resolve the issue.

Correção

Information Disclosure

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5182

Produtos afetados

Open Enterprise Server