PT-2017-17891 · Riverbed · Riverbed Opnet App Response Xpert
Publicado
2017-08-26
·
Atualizado
2017-09-02
·
CVE-2017-7693
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Riverbed OPNET App Response Xpert (ARX) version 9.6.1
Description
The issue allows remote authenticated users to inject arbitrary commands to read OS files due to a directory traversal vulnerability in viewer script.jsp.
Recommendations
For Riverbed OPNET App Response Xpert (ARX) version 9.6.1, consider restricting access to the viewer script.jsp file until a patch is available. As a temporary workaround, limit the ability to inject arbitrary commands to prevent unauthorized file access.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Riverbed Opnet App Response Xpert