PT-2017-17861 · Solarwinds · Solarwinds Log & Event Manager

Baker Hamilton

·

Publicado

2017-04-10

·

Atualizado

2017-04-17

·

CVE-2017-7646

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SolarWinds Log & Event Manager (LEM) versions prior to 6.3.1 Hotfix 4
Description The issue allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.
Recommendations For versions prior to 6.3.1 Hotfix 4, update to 6.3.1 Hotfix 4 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7646

Produtos afetados

Solarwinds Log & Event Manager