← Back

Micro Focus

micro_focus

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Vibe
vibe

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Micro Focus
1Vibe
May 13, 2026
May 18, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the...Show more
An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).Show less