Vulnerability CVE-2017-8007


Published: 2017-09-21   Modified: 2017-09-22

Description:
In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.5/10
6.4/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
EMC -> M&R 
EMC -> Storage m&r 
EMC -> Vipr srm 
EMC -> Vnx m&r 

 References:
http://seclists.org/fulldisclosure/2017/Sep/51
http://www.securityfocus.com/bid/100957
http://www.securitytracker.com/id/1039417
http://www.securitytracker.com/id/1039418

Copyright 2021, cxsecurity.com

 

Back to Top