CVE-2017-7433
Last modified
CVE-2017-7433 is a vulnerability of currently unknown severity. An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Micro Focus | Vibe | <= 4.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7433?
How severe is CVE-2017-7433?
How do I fix CVE-2017-7433?
Are you affected by CVE-2017-7433?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
