CVE-2017-7433

MEDIUM

Micro Focus Vibe <4.0.2 - Path Traversal

Title source: llm

Description

An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 48.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
micro_focus/vibe < 4.0.2
Micro Focus/Vibe < 4.0.2 and earlier
Published May 18, 2017
Tracked Since Feb 18, 2026