5
CVSSv2

CVE-2015-3897

Published: 18/06/2015 Updated: 09/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Bonita BPM Portal prior to 6.5.3 allows remote malicious users to read arbitrary files via a .. (dot dot) in the theme parameter and a file path in the location parameter to bonita/portal/themeResource.

Vulnerable Product Search on Vulmon Subscribe to Product

bonitasoft bonita bpm portal

Exploits

Advisory ID: HTB23259 Product: Bonita BPM Vendor: Bonitasoft Vulnerable Version(s): 651 and probably prior Tested Version: 651 (Windows and Mac OS packages) Advisory Publication: May 7, 2015 [without technical details] Vendor Notification: May 7, 2015 Vendor Patch: June 9, 2015 Public Disclosure: June 10, 2015 Vulnerability Type: Path ...
Bonita BPM version 651 suffers from open redirect and directory traversal vulnerabilities ...