Check Point Reference: | CPAI-2014-1830 |
Date Published: | 14 Oct 2014 |
Severity: | High |
Last Updated: | Tuesday 14 October, 2014 |
Source: | HP |
Industry Reference: | CVE-2014-2625 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | HP Network Virtualization prior to v8.61 Patch 1 |
Vulnerability Description | A directory traversal vulnerability exists in HP Network Virtualization software. The vulnerability is due to insufficient input validation of user parameters passed to "storedNtxFile" method. A remote, unauthenticated attacker can leverage this vulnerability to gain access to sensitive information on the vulnerable system by sending malicious GET requests to the server. |
SmartView Tracker will log the following entries:
Attack Name: HP Products Protection Violation.
Attack Information: HP Network Virtualization storedNtxFile Directory Traversal