CVE-2017-7433
MEDIUMMicro Focus Vibe <4.0.2 - Path Traversal
Title source: llmDescription
An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).
Scores
CVSS v3
6.5
EPSS
0.0025
EPSS Percentile
48.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
micro_focus/vibe
< 4.0.2
Micro Focus/Vibe
< 4.0.2 and earlier
Published
May 18, 2017
Tracked Since
Feb 18, 2026