PT-2016-5906 · Hewlett Packard · Hpe Performance Center+1

Published

2016-06-03

·

Updated

2017-11-03

·

CVE-2016-4360

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions HPE LoadRunner versions 11.52 through patch 3 HPE LoadRunner versions 12.00 through patch 1 HPE LoadRunner versions 12.01 through patch 3 HPE LoadRunner versions 12.02 through patch 2 HPE LoadRunner versions 12.50 through patch 3 Performance Center versions 11.52 through patch 3 Performance Center versions 12.00 through patch 1 Performance Center versions 12.01 through patch 3 Performance Center versions 12.20 through patch 2 Performance Center versions 12.50 through patch 1
Description The issue is related to the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner, where the web/admin/data.js file does not restrict file paths sent to an unlink call. This allows remote attackers to delete arbitrary files via the path parameter to "data/import csv".
Recommendations For HPE LoadRunner versions 11.52 through patch 3, update to a version after patch 3. For HPE LoadRunner versions 12.00 through patch 1, update to a version after patch 1. For HPE LoadRunner versions 12.01 through patch 3, update to a version after patch 3. For HPE LoadRunner versions 12.02 through patch 2, update to a version after patch 2. For HPE LoadRunner versions 12.50 through patch 3, update to a version after patch 3. For Performance Center versions 11.52 through patch 3, update to a version after patch 3. For Performance Center versions 12.00 through patch 1, update to a version after patch 1. For Performance Center versions 12.01 through patch 3, update to a version after patch 3. For Performance Center versions 12.20 through patch 2, update to a version after patch 2. For Performance Center versions 12.50 through patch 1, update to a version after patch 1. As a temporary workaround, consider restricting access to the "data/import csv" endpoint until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2016-4360
ZDI-16-364

Affected Products

Hp Loadrunner
Hpe Performance Center