CVE-2015-6852: Infoleak
Published Dec 28, 2015
·Updated
Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote authenticated users to read log files via a crafted parameter.
Affected Software
3 affected components
EMC Secure Remote Services=3.0
EMC Secure Remote Services=3.02
EMC Secure Remote Services=3.03
Event History
Dec 28, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6852?
CVE-2015-6852 is classified as a medium severity vulnerability due to the potential exposure of sensitive log files.
2
How do I fix CVE-2015-6852?
To fix CVE-2015-6852, upgrade EMC Secure Remote Services to version 3.10 or later.
3
Who is affected by CVE-2015-6852?
CVE-2015-6852 affects EMC Secure Remote Services Virtual Edition versions 3.0, 3.02, and 3.03.
4
What type of vulnerability is CVE-2015-6852?
CVE-2015-6852 is a directory traversal vulnerability that allows unauthorized file access.
5
Can CVE-2015-6852 be exploited remotely?
Yes, CVE-2015-6852 can be exploited by authenticated remote users.