CVE-2014-9373: Path Traversal
Published Dec 16, 2014
·Updated
Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitrary code via a .. (dot dot) in the filename.
Affected Software
1 affected component
ManageEngine NetFlow Analyzer
Event History
Dec 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9373?
CVE-2014-9373 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2014-9373?
To fix CVE-2014-9373, update to the latest version of ManageEngine NetFlow Analyzer that includes security patches addressing this vulnerability.
3
What type of attack can exploit CVE-2014-9373?
CVE-2014-9373 can be exploited via directory traversal attacks that allow unauthorized access to the file system.
4
Which software is affected by CVE-2014-9373?
CVE-2014-9373 affects ManageEngine NetFlow Analyzer.
5
Is CVE-2014-9373 difficult to exploit?
CVE-2014-9373 can be relatively easy to exploit for attackers familiar with directory traversal techniques.