CVE-2017-6636: Path Traversal
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software does not perform proper input validation of HTTP requests and fails to apply role-based access controls (RBACs) to requested HTTP URLs. An attacker could exploit this vulnerability by sending a crafted HTTP request that uses directory traversal techniques to submit a path to a desired file location on an affected system. A successful exploit could allow the attacker to view any file on the system. Cisco Bug IDs: CSCvc99604.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6636?
CVE-2017-6636 has a medium severity rating due to the potential for authenticated remote attackers to access sensitive files.
How do I fix CVE-2017-6636?
The recommended fix for CVE-2017-6636 is to upgrade to Cisco Prime Collaboration Provisioning Software version 11.1 or later.
What software versions are affected by CVE-2017-6636?
CVE-2017-6636 affects Cisco Prime Collaboration Provisioning versions 9.0.0 through 10.6.2, and version 11.0.0 prior to the update.
Can CVE-2017-6636 be exploited remotely?
Yes, CVE-2017-6636 can be exploited by an authenticated remote attacker.
What impact does CVE-2017-6636 have on affected systems?
CVE-2017-6636 allows an authenticated user to view any file on the affected system, potentially leading to data exposure.