← Vulnerability feed

Vulnerability record · CVE-2017-8007 · published 22 September 2017

CVE-2017-8007: Dell emc m\&r path traversal vulnerability

Dell · Emc M\&R

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

8.8 CVSS 3.1 High EPSS 3.0% · top 13.3% CWE-22 · Path traversal
8.8CVSS 3.1 base score, v2 6.5
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2017/Sep/51 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/100957 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039417 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039418 Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2017/Sep/51 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/100957 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039417 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1039418 Third Party AdvisoryVDB Entry

Track CVE-2017-8007 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-18580Dell emc storage monitoring and reporting deserialization of untrusted data vulnerabilityDell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated…EPSS 4.9%9.8CVE-2018-1183Dell emc smis xml external entity (xxe) vulnerabilityIn Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, D…EPSS 2.0%9.8CVE-2017-8011Dell emc m\&r hard-coded credentials vulnerabilityEMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX M&R all …EPSS 14%7.4CVE-2017-8012Dell emc m\&r vulnerabilityIn EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Java Management Extensions (JMX) protocol used to communicate …EPSS 1.9%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed

Source: NIST National Vulnerability Database (record CVE-2017-8007), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.