{"api_version":"1","generated_at":"2026-07-23T06:58:49+00:00","cve":"CVE-2017-10949","urls":{"html":"https://cve.report/CVE-2017-10949","api":"https://cve.report/api/cve/CVE-2017-10949.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-10949","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-10949"},"summary":{"title":"CVE-2017-10949","description":"Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.","state":"PUBLISHED","assigner":"zdi","published_at":"2017-08-04 15:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-22","Directory Traversal"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.zerodayinitiative.com/advisories/ZDI-17-523","name":"http://www.zerodayinitiative.com/advisories/ZDI-17-523","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/100138","name":"http://www.securityfocus.com/bid/100138","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Dell Storage Manager CVE-2017-10949 Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://topics-cdn.dell.com/pdf/dell-compellent-sc8000_release%20notes24_en-us.pdf","name":"http://topics-cdn.dell.com/pdf/dell-compellent-sc8000_release%20notes24_en-us.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes","Vendor Advisory"],"title":"404 - File or directory not found.","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-10949","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-10949","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Zero Day Initiative","product":"Dell Storage Manager","version":"affected 2016 R2.1","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"10949","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"dell","cpe5":"storage_manager_2016","cpe6":"r2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T17:50:12.840Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://topics-cdn.dell.com/pdf/dell-compellent-sc8000_release%20notes24_en-us.pdf"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-17-523"},{"name":"100138","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/100138"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Dell Storage Manager","vendor":"Zero Day Initiative","versions":[{"status":"affected","version":"2016 R2.1"}]}],"datePublic":"2017-08-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459."}],"problemTypes":[{"descriptions":[{"description":"Directory Traversal","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-05T09:57:01.000Z","orgId":"99f1926a-a320-47d8-bbb5-42feb611262e","shortName":"zdi"},"references":[{"tags":["x_refsource_MISC"],"url":"http://topics-cdn.dell.com/pdf/dell-compellent-sc8000_release%20notes24_en-us.pdf"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-17-523"},{"name":"100138","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/100138"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"zdi-disclosures@trendmicro.com","DATE_PUBLIC":"2017-08-02T00:00:00","ID":"CVE-2017-10949","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Dell Storage Manager","version":{"version_data":[{"version_value":"2016 R2.1"}]}}]},"vendor_name":"Zero Day Initiative"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Directory Traversal"}]}]},"references":{"reference_data":[{"name":"http://topics-cdn.dell.com/pdf/dell-compellent-sc8000_release%20notes24_en-us.pdf","refsource":"MISC","url":"http://topics-cdn.dell.com/pdf/dell-compellent-sc8000_release%20notes24_en-us.pdf"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-17-523","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-17-523"},{"name":"100138","refsource":"BID","url":"http://www.securityfocus.com/bid/100138"}]}}}},"cveMetadata":{"assignerOrgId":"99f1926a-a320-47d8-bbb5-42feb611262e","assignerShortName":"zdi","cveId":"CVE-2017-10949","datePublished":"2017-08-04T15:00:00.000Z","dateReserved":"2017-07-05T00:00:00.000Z","dateUpdated":"2024-09-16T23:15:55.612Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-08-04 15:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-22","Directory Traversal"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:dell:storage_manager_2016:r2.1:*:*:*:*:*:*:*","matchCriteriaId":"3875384E-E153-4430-A792-9351651C65CB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"10949","Ordinal":"1","Title":"CVE-2017-10949","CVE":"CVE-2017-10949","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"10949","Ordinal":"1","NoteData":"Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.","Type":"Description","Title":"CVE-2017-10949"},{"CveYear":"2017","CveId":"10949","Ordinal":"2","NoteData":"2017-08-04","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"10949","Ordinal":"3","NoteData":"2017-08-05","Type":"Other","Title":"Modified"}]}}}