A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.
2019-02-20T22:29:00.273
2024-11-21T04:42:06.530
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | microfocus | filr | 3.0 | Yes |
Application | microfocus | filr | 3.0 | Yes |
Application | microfocus | filr | 3.0 | Yes |
Application | microfocus | filr | 3.0 | Yes |
Application | microfocus | filr | 3.0 | Yes |
Application | microfocus | filr | 3.0 | Yes |
Operating System | suse | suse_linux_enterprise_server | 11 | No |