Path traversal in MySQL Enterprise Monitor - CVE-2016-9878

 

Path traversal in MySQL Enterprise Monitor - CVE-2016-9878

Published: April 20, 2018


Vulnerability identifier: #VU12008
CSH Severity: Low
CVSS v4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-9878
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a physical authenticated attacker to obtain potentially sensitive information on the target system.

The weakness exists due to improper sanitization of paths provided to the ResourceServlet. A physical attacker can trigger path traversal and gain access to potentially sensitive information.

Affected software

MySQL Enterprise Monitor
Fedora
springframework
IBM Engineering Requirements Management DOORS Next
IBM Cognos Controller

How to mitigate CVE-2016-9878

Install update from vendor's website.

springframework - update to 3.2.18-1.fc25
IBM Engineering Requirements Management DOORS Next - update to 9.7.2.7
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2

External References

Related Security Bulletins