In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/100957 | vdb entry third party advisory |
http://www.securitytracker.com/id/1039418 | vdb entry third party advisory |
http://seclists.org/fulldisclosure/2017/Sep/51 | third party advisory mailing list |
http://www.securitytracker.com/id/1039417 | vdb entry third party advisory |