VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-24869 VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.
Fixes

Solution

VISAM recommends users update to VBASE v11.7.0.2 or later. Users may obtain a download link by submitting a request form. For more information, please contact VISAM using the information provided on the company contact page.


Workaround

No workaround given by the vendor.

History

Thu, 17 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-17T15:50:29.866Z

Reserved: 2021-08-10T00:00:00.000Z

Link: CVE-2021-38417

cve-icon Vulnrichment

Updated: 2024-08-04T01:44:22.198Z

cve-icon NVD

Status : Modified

Published: 2022-07-27T21:15:08.577

Modified: 2025-04-17T16:15:23.727

Link: CVE-2021-38417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.