CVE-2019-3816: Path Traversal
It was found that openwsman can access various secret files without having the correct privileges set. A local attacker could use this for information disclosure.
Other sources
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to openwsman server.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3816?
CVE-2019-3816 is a vulnerability in Openwsman versions up to and including 2.6.9.
What is the severity of CVE-2019-3816?
CVE-2019-3816 has a severity level of 7.5 (high).
How does CVE-2019-3816 work?
CVE-2019-3816 allows a remote, unauthenticated attacker to exploit the vulnerability by sending a specially crafted HTTP request to the openwsman server.
Which software versions are affected by CVE-2019-3816?
Openwsman versions up to and including 2.6.9 are affected by CVE-2019-3816.
How can CVE-2019-3816 be fixed?
To fix CVE-2019-3816, users should update to a version of Openwsman that is not vulnerable.