CVE-2016-4314: Path Traversal
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-4314?
CVE-2016-4314 is classified as a high severity vulnerability due to its ability to allow unauthorized file access.
How do I fix CVE-2016-4314?
To remediate CVE-2016-4314, upgrade WSO2 Carbon to version 4.4.6 or a later version where this vulnerability is addressed.
Who is affected by CVE-2016-4314?
Any remote authenticated administrators using WSO2 Carbon version 4.4.5 are affected by CVE-2016-4314.
What type of vulnerability is CVE-2016-4314?
CVE-2016-4314 is a directory traversal vulnerability that allows access to arbitrary files on the server.
What is the impact of CVE-2016-4314?
The impact of CVE-2016-4314 includes potential disclosure of sensitive information from the filesystem.