CVE-2016-5664: Path Traversal
Published Aug 26, 2016
·Updated
Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI.
Affected Software
1 affected component
Accellion Kiteworks appliance<=kw2016.03.00
Event History
Aug 26, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5664?
CVE-2016-5664 is classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
2
How do I fix CVE-2016-5664?
To remediate CVE-2016-5664, update the Accellion Kiteworks appliance to version kw2016.03.00 or later.
3
What type of attack is possible with CVE-2016-5664?
CVE-2016-5664 allows remote attackers to exploit directory traversal to read arbitrary files on the affected system.
4
Which versions of Accellion Kiteworks are affected by CVE-2016-5664?
Accellion Kiteworks appliances before version kw2016.03.00 are vulnerable to CVE-2016-5664.
5
Is CVE-2016-5664 related to any specific software configuration?
CVE-2016-5664 affects Accellion Kiteworks appliances due to improper validation of URI inputs.