Path traversal in Cloud Optimizer - CVE-2017-8944

 

Path traversal in Cloud Optimizer - CVE-2017-8944

Published: May 23, 2017 / Updated: May 23, 2017


Vulnerability identifier: #VU6621
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-8944
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker obtain potentially sensitive information on the target system.

The weakness exists in the DownloadServlet servlet due to improper validation of user-supplied paths for file operations. A remote attacker can use undisclosed means and gain access to arbitrary files on the target system.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

Cloud Optimizer

How to mitigate CVE-2017-8944

Update to version 3.01.


External References

Related Security Bulletins