SB2018021620 - Denial of service in Reprise Licence Manager
Published: February 16, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Path traversal (CVE-ID: CVE-2018-5716)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote unauthenticated attacker to conduct a path traversal attack on the target system.
The weakness exists due to insufficient validation of web requests. A remote attacker can send a specially crafted web request, gain access to potentially sensitive information or modify license files and cause the service to crash.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.