CVE-2016-4360 Information

Description

web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3 12.00 through patch 1 12.01 through patch 3 12.02 through patch 2 and 12.50 through patch 3 and Performance Center 11.52 through patch 3 12.00 through patch 1 12.01 through patch 3 12.20 through patch 2 and 12.50 through patch 1 do not restrict file paths sent to an unlink call which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv aka ZDI-CAN-3555.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Reference

http://www.securityfocus.com/bid/90975 http://www.securitytracker.com/id/1036006 http://www.zerodayinitiative.com/advisories/ZDI-16-364 https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423 https://www.tenable.com/security/research/tra-2016-17

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.1

Share on: