« Volver al listado

CVE-2016-4360

Estado: ModificadaCrítica (9.1)—

web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 do not restrict file paths sent to an unlink call, which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv, aka ZDI-CAN-3555.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-4360",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": true,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.1,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-06-08T14:59:42.313",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/90975",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1036006",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-16-364",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2016-17",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/90975",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1036006",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-16-364",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://h20566.www2.hpe.com/hpsc/doc/public/display?docId=emr_na-c05157423",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.tenable.com/security/research/tra-2016-17",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 do not restrict file paths sent to an unlink call, which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv, aka ZDI-CAN-3555."
    },
    {
      "lang": "es",
      "value": "web/admin/data.js en el componente Performance Center Virtual Table Server (VTS) en HPE LoadRunner 11.52 hasta el parche 3, 12.00 hasta el parche 1, 12.01 hasta el parche 3, 12.02 hasta el parche 2 y 12.50 hasta el parche 3 y Performance Center 11.52 hasta el parche 3, 12.00 hasta el parche 1, 12.01 hasta el parche 3, 12.20 hasta el parche 2 y 12.50 hasta el parche 1 no restringe rutas de archivo enviadas a un llamada desvinculada, lo que permite a atacantes remotos borrar archivos arbitrarios a través del parámetro de ruta a data/import_csv, también conocido como ZDI-CAN-3555."
    }
  ],
  "lastModified": "2026-06-17T00:47:24.897",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:loadrunner:11.52:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA41E4F9-3325-4665-A433-BDAA02621F13"
            },
            {
              "criteria": "cpe:2.3:a:hp:loadrunner:12.00:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58DEE82F-A703-4F0D-96D4-47E6DEC473BC"
            },
            {
              "criteria": "cpe:2.3:a:hp:loadrunner:12.01:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B9BA232-B8DD-4EC9-991F-06E73774A156"
            },
            {
              "criteria": "cpe:2.3:a:hp:loadrunner:12.02:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7226CD8-1528-4C5B-825D-2569D025808C"
            },
            {
              "criteria": "cpe:2.3:a:hp:loadrunner:12.50:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7772F623-E8AD-41A1-B5E2-F507FB7F413B"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:hp:performance_center:11.52:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BACEBCB-93A4-4C8C-90DD-3D233BF9B128"
            },
            {
              "criteria": "cpe:2.3:a:hp:performance_center:12.00:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "27EAC034-46D2-41A8-A3F5-7ABDCC7E9457"
            },
            {
              "criteria": "cpe:2.3:a:hp:performance_center:12.01:p3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0DEA9F8-EF3D-4C7F-B6B9-F9A33341E9A5"
            },
            {
              "criteria": "cpe:2.3:a:hp:performance_center:12.20:p2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7FCF452-A5B1-4CB5-BD02-785670A04E82"
            },
            {
              "criteria": "cpe:2.3:a:hp:performance_center:12.50:p1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "235AB949-A179-48FC-BFAA-7796578E430D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}