An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-16457 | An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.novell.com/support/kb/doc.php?id=7019005 |
|
History
No history.
Status: PUBLISHED
Assigner: microfocus
Published:
Updated: 2024-08-05T16:04:11.272Z
Reserved: 2017-04-05T00:00:00.000Z
Link: CVE-2017-7433
No data.
Status : Deferred
Published: 2017-05-18T14:29:00.167
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7433
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD