CVE-2017-7646: Infoleak
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Log & Event Manager (LEM)to a version that resolves this vulnerability.Fixed in 6.3.1 Hotfix 4
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7646?
CVE-2017-7646 is classified as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2017-7646?
To fix CVE-2017-7646, upgrade to SolarWinds Log & Event Manager version 6.3.1 Hotfix 4 or later.
Who is affected by CVE-2017-7646?
CVE-2017-7646 affects users of SolarWinds Log & Event Manager versions prior to 6.3.1 Hotfix 4.
What is the impact of CVE-2017-7646?
The impact of CVE-2017-7646 allows authenticated users to access the server's filesystem and view arbitrary files.
When was CVE-2017-7646 discovered?
CVE-2017-7646 was published on March 23, 2017.