In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Sep/51 | Mailing List Third Party Advisory |
http://www.securitytracker.com/id/1039418 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1039417 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/100957 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-09-21 18:29
Updated : 2021-09-13 05:07
NVD link : CVE-2017-8007
Mitre link : CVE-2017-8007
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
dell
- emc_storage_monitoring_and_reporting
- emc_vipr_srm
- emc_m\&r
- emc_vnx_monitoring_and_reporting