CVE-2016-5332: Path Traversal
Published Aug 31, 2016
·Updated
Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
Affected Software
5 affected components
VMware vRealize Log Insight=2.0
VMware vRealize Log Insight=2.0.5
VMware vRealize Log Insight=2.5
VMware vRealize Log Insight=3.0
VMware vRealize Log Insight=3.3
Remediation
Event History
Aug 31, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5332?
CVE-2016-5332 has been rated as a high severity vulnerability due to its potential to allow unauthorized access to sensitive files.
2
How do I fix CVE-2016-5332?
To fix CVE-2016-5332, upgrade your VMware vRealize Log Insight to version 3.6.0 or later.
3
What software is affected by CVE-2016-5332?
CVE-2016-5332 affects VMware vRealize Log Insight versions 2.x and 3.x prior to version 3.6.0.
4
Can CVE-2016-5332 be exploited remotely?
Yes, CVE-2016-5332 can be exploited by remote attackers to read arbitrary files on the affected system.
5
What types of attacks does CVE-2016-5332 enable?
CVE-2016-5332 enables directory traversal attacks which could expose sensitive information on the server.