CVE-2017-8007 Information
Feb 14, 2021
cve
Description
In EMC ViPR SRM Storage M&R VNX M&R and M&R (Watch4Net) for SAS Solution Packs the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information and modify or delete data by supplying specially crafted strings in input parameters of the web service call.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://seclists.org/fulldisclosure/2017/Sep/51 http://www.securityfocus.com/bid/100957 http://www.securitytracker.com/id/1039417 http://www.securitytracker.com/id/1039418
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: