CVE-2017-13984

An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hp:bsm_platform_application_performance_management_system_health:9.26:*:*:*:*:*:*:*
cpe:2.3:a:hp:bsm_platform_application_performance_management_system_health:9.30:*:*:*:*:*:*:*
cpe:2.3:a:hp:bsm_platform_application_performance_management_system_health:9.40:*:*:*:*:*:*:*

History

07 Nov 2023, 02:38

Type Values Removed Values Added
References (AUSCERT) https://www.auscert.org.au/bulletins/52154 - Third Party Advisory () https://www.auscert.org.au/bulletins/52154 -
References (MISC) http://www.zerodayinitiative.com/advisories/ZDI-17-720/ - Third Party Advisory, VDB Entry () http://www.zerodayinitiative.com/advisories/ZDI-17-720/ -
References (CONFIRM) https://softwaresupport.hpe.com/km/KM02942065 - Permissions Required () https://softwaresupport.hpe.com/km/KM02942065 -

Information

Published : 2017-09-30 01:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-13984

Mitre link : CVE-2017-13984

CVE.ORG link : CVE-2017-13984


JSON object : View

Products Affected

hp

  • bsm_platform_application_performance_management_system_health
CWE
CWE-287

Improper Authentication