CVE-2021-38417: VISAM VBASE Editor Improper Access Control
Published Jul 27, 2022
·Updated
VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.
Affected Software
2 affected components
VISAM VBASE Pro-RT/ Server-RT (Web Remote)=11.6.0.6
VISAM VBASE Web-Remote=11.6.0.6
Remediation
Information
VISAM recommends users update to VBASE v11.7.0.2 or later. Users may obtain a download link by submitting a request form.
For more information, please contact VISAM using the information provided on the company contact page.
Event History
Jul 27, 2022
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-38417?
CVE-2021-38417 has a severity rating of medium due to its improper access control vulnerabilities.
2
How do I fix CVE-2021-38417?
To fix CVE-2021-38417, you should implement proper access controls to restrict unauthenticated user access to sensitive directories and files.
3
Who is affected by CVE-2021-38417?
CVE-2021-38417 affects users of VISAM VBASE version 11.6.0.6 using the web-remote endpoint.
4
What type of vulnerability is CVE-2021-38417?
CVE-2021-38417 is classified as an improper access control vulnerability.
5
Can CVE-2021-38417 be exploited remotely?
Yes, CVE-2021-38417 can be exploited remotely by unauthenticated users to access restricted folders and files.