CVE-2016-4360
web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 do not restrict file paths sent to an unlink call, which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv, aka ZDI-CAN-3555.
- CVSS 3.0
- 9.1 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 8.57% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- hp/loadrunner · hp/performance center
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/90975
- http://www.securitytracker.com/id/1036006Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-364Third Party Advisory, VDB Entry
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423Vendor Advisory
- https://www.tenable.com/security/research/tra-2016-17
- http://www.securityfocus.com/bid/90975
- http://www.securitytracker.com/id/1036006Third Party Advisory, VDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-16-364Third Party Advisory, VDB Entry
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423Vendor Advisory
- https://www.tenable.com/security/research/tra-2016-17
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.