An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remote authenticated administrator to read arbitrary files on the system via Directory Traversal. By manipulating the resource name in GET requests referring to files with absolute paths, it is possible to access arbitrary files stored on the filesystem, including application source code, configuration files, and critical system files.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-03-04T18:23:26
Updated: 2024-08-03T05:03:32.801Z
Reserved: 2022-03-04T00:00:00
Link: CVE-2022-26484
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-04T19:15:09.107
Modified: 2024-11-21T06:54:02.200
Link: CVE-2022-26484
Redhat
No data.