Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.
Vulnerabilidad de salto de directorio en SafeNet Sentinel Protection Server 7.0.0 hasta 7.4.0 y versiones anteriores, y Sentinel Keys Server 1.0.3 y posiblemente versiones anteriores, permite a atacantes remotos leer ficheros de su elección mediante un .. (punto punto) en la cadena de consulta.
AV:N/AC:L/Au:N/C:N/I:P/A:N
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | PARTIAL |
| Availability Impact | NONE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
CWE-22
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| safenet | sentinel_keys_server | 1.0.3 | <built-in method update of dict object at 0x7763d8713480> | Application |
| safenet | sentinel_protection_server | 7.0 | <built-in method update of dict object at 0x7763a1fe9840> | Application |
| safenet | sentinel_protection_server | 7.1 | <built-in method update of dict object at 0x7763d87110c0> | Application |
| safenet | sentinel_protection_server | 7.2 | <built-in method update of dict object at 0x7763d8b460c0> | Application |
| safenet | sentinel_protection_server | 7.3 | <built-in method update of dict object at 0x7763d8712d00> | Application |
| safenet | sentinel_protection_server | 7.4 | <built-in method update of dict object at 0x7763d8b8a040> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:safenet:sentinel_keys_server:1.0.3:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:safenet:sentinel_protection_server:7.0:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:safenet:sentinel_protection_server:7.1:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:safenet:sentinel_protection_server:7.2:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:safenet:sentinel_protection_server:7.3:*:*:*:*:*:*:* |
| Yes | cpe:2.3:a:safenet:sentinel_protection_server:7.4:*:*:*:*:*:*:* |