Path Traversal Vulnerability in Micro Focus Enterprise Developer and Server
CVE-2017-7424
6.5MEDIUM
What is CVE-2017-7424?
A Path Traversal vulnerability exists in the esfadmingui component of Micro Focus Enterprise Developer and Enterprise Server. This issue allows remote authenticated users to exploit the vulnerability to download arbitrary files from the underlying system, provided the esfadmingui component is enabled. Note that this component is not enabled by default, but if configured, it poses a significant risk as it grants access to sensitive files. Proper security measures and configurations should be reviewed to mitigate potential exploitation.
Affected Version(s)
Micro Focus Enterprise Developer, Micro Focus Enterprise Server All versions before 2.3 Update 1, 2.3 Update 1 before Hotfix 8, 2.3 Update 2 before Hotfix 9