CVE-2020-7008: Path Traversal
Published Apr 3, 2020
·Updated
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
Affected Software
2 affected components
VISAM VBASE Editor=11.5.0.2
VISAM VBASE Web-Remote
Event History
Apr 3, 2020
CVE Published
via MITRE·05:44 PM
Data Sourced
via MITRE·05:44 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-7008?
The severity of CVE-2020-7008 is high with a CVSS score of 7.5.
2
How can I exploit CVE-2020-7008?
An attacker can exploit CVE-2020-7008 by passing input in the URL to read arbitrary files from local resources.
3
How do I fix CVE-2020-7008?
To fix CVE-2020-7008, update to a version of VISAM VBASE Editor and VBASE Web-Remote Module that properly verifies input passed in the URL.