PT-2017-8468 · Wso2 · Wso2 Carbon

Hyp3Rlinx

+1

·

Publicado

2017-02-16

·

Atualizado

2022-05-14

·

CVE-2016-4314

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WSO2 Carbon version 4.4.5
Description A directory traversal issue exists in the LogViewer Admin Service, allowing remote authenticated administrators to read arbitrary files. This is achieved by using a .. (dot dot) in the logFile parameter to the "downloadgz-ajaxprocessor.jsp" endpoint.
Recommendations For WSO2 Carbon version 4.4.5, consider restricting access to the LogViewer Admin Service until a patch is available. As a temporary workaround, avoid using the logFile parameter in the downloadgz-ajaxprocessor.jsp endpoint to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-4314
GHSA-MJWW-VQQW-V78Q

Produtos afetados

Wso2 Carbon