CVE-2019-3474
Published Feb 20, 2019
Last updated a year ago
Overview
- Description
- A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.
- Source
- security@opentext.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 2.9
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:N/A:N
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microfocus:filr:3.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "58764C6E-A22A-4732-8707-4D2E9F7112F4" }, { "criteria": "cpe:2.3:a:microfocus:filr:3.0:update_1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4890BAB5-1505-4FC3-92B5-EB08FDE93DC7" }, { "criteria": "cpe:2.3:a:microfocus:filr:3.0:update_2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F8437EBB-AAC3-4E10-BD30-7E41FED762A6" }, { "criteria": "cpe:2.3:a:microfocus:filr:3.0:update_3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F05D20C-3CEA-4A9A-AC7E-7233BA58E624" }, { "criteria": "cpe:2.3:a:microfocus:filr:3.0:update_4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B842ABF3-85AE-4369-9997-F3A5982F9F6C" }, { "criteria": "cpe:2.3:a:microfocus:filr:3.0:update_5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BD7B9AE-7249-44B5-9A99-E2EC85E4A723" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:suse:suse_linux_enterprise_server:11:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "93AD897C-C9F7-4B4D-BC39-5E13920383D4" } ], "operator": "OR" } ], "operator": "AND" } ]