PT-2017-7883 · Opsview · Opsview Monitor Pro

Published

2017-05-03

·

Updated

2017-05-17

·

CVE-2016-10367

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Opsview Monitor Pro versions prior to 5.1.0.162300841 Opsview Monitor Pro versions prior to 5.0.2.27475 Opsview Monitor Pro versions prior to 4.6.4.162391051 Opsview Monitor Pro version 4.5.x without a certain 2016 security patch
Description An unauthenticated Directory Traversal issue can be exploited by issuing a specially crafted HTTP GET request. The attack utilizes a simple URL encoding bypass, using %252f instead of /.
Recommendations For versions prior to 5.1.0.162300841, update to version 5.1.0.162300841 or later. For versions prior to 5.0.2.27475, update to version 5.0.2.27475 or later. For versions prior to 4.6.4.162391051, update to version 4.6.4.162391051 or later. For version 4.5.x, apply the certain 2016 security patch to mitigate the issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10367

Affected Products

Opsview Monitor Pro