An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).
References
Configurations
History
21 Nov 2024, 03:31
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.novell.com/support/kb/doc.php?id=7019005 - |
07 Nov 2023, 02:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.novell.com/support/kb/doc.php?id=7019005 - |
Information
Published : 2017-05-18 14:29
Updated : 2024-11-21 03:31
NVD link : CVE-2017-7433
Mitre link : CVE-2017-7433
CVE.ORG link : CVE-2017-7433
JSON object : View
Products Affected
micro_focus
- vibe
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')