{"api_version":"1","generated_at":"2026-07-23T08:09:04+00:00","cve":"CVE-2016-7843","urls":{"html":"https://cve.report/CVE-2016-7843","api":"https://cve.report/api/cve/CVE-2016-7843.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-7843","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-7843"},"summary":{"title":"CVE-2016-7843","description":"Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.","state":"PUBLISHED","assigner":"jpcert","published_at":"2017-04-28 16:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-22","Directory traversal"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/95445","name":"http://www.securityfocus.com/bid/95445","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Multiple AttacheCase Products CVE-2016-7843 Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://jvn.jp/en/jp/JVN28331227/index.html","name":"http://jvn.jp/en/jp/JVN28331227/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"JVN#28331227: MaruUo Factory's multiple AttacheCase products vulnerable to directory traversal","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://maruuofactory.life.coocan.jp/attachecase/#pathTraversal","name":"http://maruuofactory.life.coocan.jp/attachecase/#pathTraversal","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"アタッシェケース for Java","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-7843","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-7843","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MaruUo Factory","product":"AttacheCase for Java","version":"affected Ver0.60 and earlier","platforms":[]},{"source":"CNA","vendor":"MaruUo Factory","product":"AttacheCase Lite","version":"affected Ver1.4.6 and earlier","platforms":[]},{"source":"CNA","vendor":"MaruUo Factory","product":"AttacheCase Pro","version":"affected Ver1.5.7 and earlier","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"7843","vulnerable":"1","versionEndIncluding":"0.6.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hibara_software","cpe5":"attachecase_for_java","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"7843","vulnerable":"1","versionEndIncluding":"1.4.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hibara_software","cpe5":"attachecase_lite","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"7843","vulnerable":"1","versionEndIncluding":"1.5.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hibara_software","cpe5":"attachecase_pro","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T02:04:56.201Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"JVN#28331227","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN28331227/index.html"},{"name":"95445","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/95445"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://maruuofactory.life.coocan.jp/attachecase/#pathTraversal"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"AttacheCase for Java","vendor":"MaruUo Factory","versions":[{"status":"affected","version":"Ver0.60 and earlier"}]},{"product":"AttacheCase Lite","vendor":"MaruUo Factory","versions":[{"status":"affected","version":"Ver1.4.6 and earlier"}]},{"product":"AttacheCase Pro","vendor":"MaruUo Factory","versions":[{"status":"affected","version":"Ver1.5.7 and earlier"}]}],"datePublic":"2017-04-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file."}],"problemTypes":[{"descriptions":[{"description":"Directory traversal","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-05-01T09:57:02.000Z","orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert"},"references":[{"name":"JVN#28331227","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN28331227/index.html"},{"name":"95445","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/95445"},{"tags":["x_refsource_MISC"],"url":"http://maruuofactory.life.coocan.jp/attachecase/#pathTraversal"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"vultures@jpcert.or.jp","ID":"CVE-2016-7843","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"AttacheCase for Java","version":{"version_data":[{"version_value":"Ver0.60 and earlier"}]}},{"product_name":"AttacheCase Lite","version":{"version_data":[{"version_value":"Ver1.4.6 and earlier"}]}},{"product_name":"AttacheCase Pro","version":{"version_data":[{"version_value":"Ver1.5.7 and earlier"}]}}]},"vendor_name":"MaruUo Factory"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Directory traversal"}]}]},"references":{"reference_data":[{"name":"JVN#28331227","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN28331227/index.html"},{"name":"95445","refsource":"BID","url":"http://www.securityfocus.com/bid/95445"},{"name":"http://maruuofactory.life.coocan.jp/attachecase/#pathTraversal","refsource":"MISC","url":"http://maruuofactory.life.coocan.jp/attachecase/#pathTraversal"}]}}}},"cveMetadata":{"assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","assignerShortName":"jpcert","cveId":"CVE-2016-7843","datePublished":"2017-04-28T16:00:00.000Z","dateReserved":"2016-09-09T00:00:00.000Z","dateUpdated":"2024-08-06T02:04:56.201Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-04-28 16:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-22","Directory traversal"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hibara_software:attachecase_for_java:*:*:*:*:*:*:*:*","versionEndIncluding":"0.6.0","matchCriteriaId":"C0F53FAA-2F3D-4BFB-9AD1-7FFAF89CCCFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:hibara_software:attachecase_lite:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.6","matchCriteriaId":"A339A10E-9444-48CB-AE4E-4FCD670E6840"},{"vulnerable":true,"criteria":"cpe:2.3:a:hibara_software:attachecase_pro:*:*:*:*:*:*:*:*","versionEndIncluding":"1.5.7","matchCriteriaId":"2A978775-089D-40E0-B122-0EED6049AFCA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"7843","Ordinal":"1","Title":"CVE-2016-7843","CVE":"CVE-2016-7843","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"7843","Ordinal":"1","NoteData":"Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.","Type":"Description","Title":"CVE-2016-7843"},{"CveYear":"2016","CveId":"7843","Ordinal":"2","NoteData":"2017-04-28","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"7843","Ordinal":"3","NoteData":"2017-05-01","Type":"Other","Title":"Modified"}]}}}