PT-2017-8468 · Wso2 · Wso2 Carbon

Hyp3Rlinx

+1

·

Published

2017-02-16

·

Updated

2022-05-14

·

CVE-2016-4314

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WSO2 Carbon version 4.4.5
Description A directory traversal issue exists in the LogViewer Admin Service, allowing remote authenticated administrators to read arbitrary files. This is achieved by using a .. (dot dot) in the logFile parameter to the "downloadgz-ajaxprocessor.jsp" endpoint.
Recommendations For WSO2 Carbon version 4.4.5, consider restricting access to the LogViewer Admin Service until a patch is available. As a temporary workaround, avoid using the logFile parameter in the downloadgz-ajaxprocessor.jsp endpoint to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4314
GHSA-MJWW-VQQW-V78Q

Affected Products

Wso2 Carbon