CVE ID | |
CVSS SCORE | 7.8, AV:N/AC:L/Au:N/C:C/I:N/A:N |
AFFECTED VENDORS |
Borland |
AFFECTED PRODUCTS |
StarTeam |
VULNERABILITY DETAILS |
The specific flaw exists within the AttachmentService servlet in the FILECHECKOUT operation. The performCheckoutFile() function allows for reading and subsequent deletion of an arbitrary file by specifying the file path. A remote attacker can exploit this vulnerability to disclose files from the system. |
ADDITIONAL DETAILS |
Vendor Contact Timeline: -- Mitigation: |
DISCLOSURE TIMELINE |
|
CREDIT | Andrea Micalizzi aka rgod |