PT-2017-17861 · Solarwinds · Solarwinds Log & Event Manager

Baker Hamilton

·

Published

2017-04-10

·

Updated

2017-04-17

·

CVE-2017-7646

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SolarWinds Log & Event Manager (LEM) versions prior to 6.3.1 Hotfix 4
Description The issue allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.
Recommendations For versions prior to 6.3.1 Hotfix 4, update to 6.3.1 Hotfix 4 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-7646

Affected Products

Solarwinds Log & Event Manager