Micro Focus · Micro Focus Filr · CVE-2019-3474
**Name of the Vulnerable Software and Affected Versions**
Micro Focus Filr versions 3.x prior to Security Update 6
**Description**
A path traversal issue in the web application component allows a remote attacker, authenticated as a low-privilege user, to download arbitrary files from the server.
**Recommendations**
For versions 3.x prior to Security Update 6, apply Security Update 6 to resolve the issue.