CVE-2015-2166: Path Traversal
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2166?
CVE-2015-2166 has been classified as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2015-2166?
To remediate CVE-2015-2166, update the Ericsson Drutt Mobile Service Delivery Platform to a version that contains the necessary security patches.
What is the impact of CVE-2015-2166?
CVE-2015-2166 allows remote attackers to exploit directory traversal to read arbitrary files on the server.
Which versions of Ericsson Drutt Mobile Service Delivery Platform are affected by CVE-2015-2166?
CVE-2015-2166 affects versions 4.0, 5.0, and 6.0 of the Ericsson Drutt Mobile Service Delivery Platform.
Can I report an exploitation of CVE-2015-2166?
Yes, if you suspect an exploitation of CVE-2015-2166, it is crucial to report it to your security team for further investigation.