CVE-2015-2121

HP Network Virtualization 8.61 and 11.52 - Arbitrary File Read via HttpServlet or NetworkEditorController

Title source: llm
STIX 2.1

Description

HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569.

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
http://zerodayinitiative.com/advisories/ZDI-15-192/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/74583

Scores

EPSS 0.0111
EPSS Percentile 78.4%

Details

CWE
CWE-200
Status published
Products (2)
hp/network_virtualization 8.61
hp/network_virtualization 11.52
Published May 25, 2015
Tracked Since Feb 18, 2026