First published: Wed Jan 21 2015(Updated: )
Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authenticated users to read arbitrary files via a crafted URL.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC ViPR SRM | <=3.6.0 | |
EMC Watch4Net | <=6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0516 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2015-0516, upgrade the EMC M&R (Watch4Net) to version 6.5u1 or later and ViPR SRM to version 3.6.1 or later.
CVE-2015-0516 affects users of EMC ViPR SRM versions prior to 3.6.1 and EMC Watch4Net versions prior to 6.5u1.
CVE-2015-0516 is a directory traversal vulnerability that allows remote authenticated users to access arbitrary files.
Attackers can exploit CVE-2015-0516 by crafting a specific URL that leverages the directory traversal flaw to read unauthorized files.