CVE-2016-4360 Information
Description
web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3 12.00 through patch 1 12.01 through patch 3 12.02 through patch 2 and 12.50 through patch 3 and Performance Center 11.52 through patch 3 12.00 through patch 1 12.01 through patch 3 12.20 through patch 2 and 12.50 through patch 1 do not restrict file paths sent to an unlink call which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv aka ZDI-CAN-3555.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Reference
http://www.securityfocus.com/bid/90975 http://www.securitytracker.com/id/1036006 http://www.zerodayinitiative.com/advisories/ZDI-16-364 https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423 https://www.tenable.com/security/research/tra-2016-17
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.1
Share on: