PT-2017-17729 · Micro Focus · Micro Focus Enterprise Server+1

Published

2017-08-21

·

Updated

2019-10-09

·

CVE-2017-7424

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Micro Focus Enterprise Developer and Enterprise Server versions 2.3 through 2.3 Update 2 before Hotfix 9
Description A Path Traversal issue allows remote authenticated users to download arbitrary files from a system running the product, given that the esfadmingui component is configured. Note that esfadmingui is not enabled by default.
Recommendations For versions 2.3 through 2.3 Update 2 before Hotfix 9, apply Hotfix 8 for 2.3 Update 1 or Hotfix 9 for 2.3 Update 2 to resolve the issue. As a temporary workaround, consider disabling the esfadmingui component until a patch is available.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7424

Affected Products

Micro Focus Enterprise Developer
Micro Focus Enterprise Server