Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3474


A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.


Published

2019-02-20T22:29:00.273

Last Modified

2024-11-21T04:42:06.530

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application microfocus filr 3.0 Yes
Application microfocus filr 3.0 Yes
Application microfocus filr 3.0 Yes
Application microfocus filr 3.0 Yes
Application microfocus filr 3.0 Yes
Application microfocus filr 3.0 Yes
Operating System suse suse_linux_enterprise_server 11 No

References