CVE-2017-10949

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
04/08/2017
Last modified:
20/04/2025

Description

Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:storage_manager_2016:r2.1:*:*:*:*:*:*:*