Junglewise Threat Intelligence

CVE-2017-5182: Micro Focus Open Enterprise Server directory traversal in Remote Manager

CVE-2017-5182 · Severity: high · CVSS 7.5 · Published 2017-01-23

Executive brief

A directory traversal vulnerability in the Remote Manager component of Micro Focus Open Enterprise Server (OES) allows unauthorized individuals to access any file on the server. This could lead to the exposure of sensitive system configuration files, credentials, or customer data. The issue affects multiple versions of the OES platform used for enterprise file and print services.

Technical details

A directory traversal vulnerability (CWE-22) exists in the Remote Manager (NRM) component of Micro Focus Open Enterprise Server. The flaw is caused by improper validation of input within URLs, allowing an unauthenticated remote attacker to bypass directory restrictions. By sending a specially crafted HTTP request, an attacker can read arbitrary files on the underlying Linux filesystem with the privileges of the Remote Manager process. This leads to total information disclosure of sensitive system files. Patches have been released for OES 2015, OES 11, and OES 2 SP3.

Affected products

  • Micro Focus Open Enterprise Server (OES) Linux OES 2015 SP1 before Maintenance Update 11080, OES 2015 before Maintenance Update 11079, OES 11 SP3 before Maintenance Update 11078, OES 11 SP2 before Maintenance Update 11077, OES 2 SP3

Timeline

  • 2017-01-20: advisory: Micro Focus published security bulletin 7018503
  • 2017-01-23: disclosed: NVD published the CVE record

References