PT-2017-17891 · Riverbed · Riverbed Opnet App Response Xpert
Published
2017-08-26
·
Updated
2017-09-02
·
CVE-2017-7693
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Riverbed OPNET App Response Xpert (ARX) version 9.6.1
Description
The issue allows remote authenticated users to inject arbitrary commands to read OS files due to a directory traversal vulnerability in viewer script.jsp.
Recommendations
For Riverbed OPNET App Response Xpert (ARX) version 9.6.1, consider restricting access to the viewer script.jsp file until a patch is available. As a temporary workaround, limit the ability to inject arbitrary commands to prevent unauthorized file access.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Riverbed Opnet App Response Xpert