CVE-2017-5966: Path Traversal
Published May 23, 2017
·Updated
Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack on sitecore/shell/download.aspx with the file parameter.
Affected Software
1 affected component
Sitecore CRM=8.1
Event History
May 23, 2017
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-5966?
CVE-2017-5966 is classified as a high-severity vulnerability due to its ability to allow remote authenticated administrators to exploit file traversal weaknesses.
2
How do I fix CVE-2017-5966?
To fix CVE-2017-5966, apply the latest security patches provided by Sitecore for CRM version 8.1.
3
What types of attacks can CVE-2017-5966 facilitate?
CVE-2017-5966 can facilitate an absolute path traversal attack, which might allow sensitive file exposure.
4
Is CVE-2017-5966 specific to any version of Sitecore CRM?
Yes, CVE-2017-5966 specifically affects Sitecore CRM version 8.1.
5
Who is affected by CVE-2017-5966?
Remote authenticated administrators using Sitecore CRM 8.1 are primarily affected by CVE-2017-5966.