CVE-2017-5182
Last modified
CVE-2017-5182 is a vulnerability of currently unknown severity. Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all versions of OES for linux, it applies to OES2015 SP1 before Maintenance Update 11080, OES2015 before Maintenance Update 11079, OES11 SP3 before Maintenance Update 11078, OES11 SP2 before Maintenance Update 11077).. EPSS estimates a 3.15% chance of exploitation in the next 30 days.
Description
Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all versions of OES for linux, it applies to OES2015 SP1 before Maintenance Update 11080, OES2015 before Maintenance Update 11079, OES11 SP3 before Maintenance Update 11078, OES11 SP2 before Maintenance Update 11077).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Novell | Open Enterprise Server | 2.0 |
| Novell | Open Enterprise Server | 2015 |
| Novell | Open Enterprise Server | 11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5182?
How severe is CVE-2017-5182?
How do I fix CVE-2017-5182?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-5176A DLL Hijack issue was discovered in Rockwell Automation Con…
- CVE-2017-5177A Stack Buffer Overflow issue was discovered in VIPA Control…
- CVE-2017-5178An issue was discovered in Schneider Electric Tableau Server…
- CVE-2017-5179Cross-site scripting (XSS) vulnerability in Tenable Nessus b…
- CVE-2017-5180Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LT…
- CVE-2017-5181Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-5183NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when con…
- CVE-2017-5184A vulnerability was discovered in NetIQ Sentinel Server 8.0 …
- CVE-2017-5185A vulnerability was discovered in NetIQ Sentinel Server 8.0 …
- CVE-2017-5186Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x b…
- CVE-2017-5187A Cross-Site Request Forgery (CWE-352) vulnerability in Dire…
- CVE-2017-5188The bs_worker code in open build service before 20170320 fol…5
Are you affected by CVE-2017-5182?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
