CVE-2017-9447: Path Traversal
In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness to read arbitrary files from the vulnerable system using path traversal sequences.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-9447?
CVE-2017-9447 refers to a vulnerability in the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140.
What is the severity of CVE-2017-9447?
CVE-2017-9447 has a severity rating of 7.5 (High).
How does CVE-2017-9447 impact Parallels Remote Application Server?
CVE-2017-9447 allows a remote, unauthenticated attacker to read arbitrary files on the server.
How can the vulnerability CVE-2017-9447 be exploited?
CVE-2017-9447 can be exploited by requesting a resource under the "RASHTML5Gateway" directory without proper file path validation.
Is there a fix available for CVE-2017-9447?
It is recommended to update to a version of Parallels Remote Application Server (RAS) that is not affected by CVE-2017-9447.