CVE-2014-8871: Path Traversal
Published Aug 28, 2017
·Updated
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier.
Affected Software
7 affected components
SAP Hybris>=5.0.0<=5.0.0.3
SAP Hybris>=5.0.3<=5.0.3.3
SAP Hybris>=5.0.4<=5.0.4.4
SAP Hybris>=5.1.0<=5.1.0.1
SAP Hybris>=5.1.1<=5.1.1.2
SAP Hybris>=5.2.0<=5.2.0.3
SAP Hybris>=5.3.0<=5.3.0.1
Event History
Aug 28, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8871?
CVE-2014-8871 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2014-8871?
To fix CVE-2014-8871, upgrade the hybris Commerce software to version 5.0.4.5 or higher.
3
What does CVE-2014-8871 affect?
CVE-2014-8871 affects SAP hybris Commerce software versions 5.0.0.3 and earlier, up to 5.3.0.1 and earlier.
4
What type of vulnerability is CVE-2014-8871?
CVE-2014-8871 is a directory traversal vulnerability that allows attackers to access restricted files.
5
Can CVE-2014-8871 be exploited remotely?
Yes, CVE-2014-8871 can potentially be exploited remotely without authentication, making it a significant risk.