CVE-2017-13984

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:bsm_platform_application_performance_management_system_health:9.26:*:*:*:*:*:*:*
cpe:2.3:a:hp:bsm_platform_application_performance_management_system_health:9.30:*:*:*:*:*:*:*
cpe:2.3:a:hp:bsm_platform_application_performance_management_system_health:9.40:*:*:*:*:*:*:*

History

21 Nov 2024, 03:11

Type Values Removed Values Added
References () http://www.zerodayinitiative.com/advisories/ZDI-17-720/ - () http://www.zerodayinitiative.com/advisories/ZDI-17-720/ -
References () https://softwaresupport.hpe.com/km/KM02942065 - () https://softwaresupport.hpe.com/km/KM02942065 -
References () https://www.auscert.org.au/bulletins/52154 - () https://www.auscert.org.au/bulletins/52154 -

07 Nov 2023, 02:38

Type Values Removed Values Added
References (AUSCERT) https://www.auscert.org.au/bulletins/52154 - Third Party Advisory () https://www.auscert.org.au/bulletins/52154 -
References (CONFIRM) https://softwaresupport.hpe.com/km/KM02942065 - Permissions Required () https://softwaresupport.hpe.com/km/KM02942065 -
References (MISC) http://www.zerodayinitiative.com/advisories/ZDI-17-720/ - Third Party Advisory, VDB Entry () http://www.zerodayinitiative.com/advisories/ZDI-17-720/ -

Information

Published : 2017-09-30 01:29

Updated : 2024-11-21 03:11


NVD link : CVE-2017-13984

Mitre link : CVE-2017-13984

CVE.ORG link : CVE-2017-13984


JSON object : View

Products Affected

hp

  • bsm_platform_application_performance_management_system_health
CWE
CWE-287

Improper Authentication