PT-2022-17896 · Veritas · Veritas Infoscale Operations Manager
Published
2022-03-04
·
Updated
2022-03-12
·
CVE-2022-26484
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Veritas InfoScale Operations Manager versions prior to 7.4.2 Patch 600
Veritas InfoScale Operations Manager versions 8.x prior to 8.0.0 Patch 100
Description
The web server in Veritas InfoScale Operations Manager fails to sanitize input data for the "admin/cgi-bin/rulemgr.pl/getfile/" endpoint, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. This can be achieved by manipulating the resource name in GET requests referring to files with absolute paths, potentially accessing application source code, configuration files, and critical system files.
Recommendations
For versions prior to 7.4.2 Patch 600, update to 7.4.2 Patch 600 or later.
For versions 8.x prior to 8.0.0 Patch 100, update to 8.0.0 Patch 100 or later.
As a temporary workaround, consider restricting access to the "admin/cgi-bin/rulemgr.pl/getfile/" endpoint until a patch is applied.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veritas Infoscale Operations Manager