CVE-2016-9177
Spark: Directory traversal vulnerability in version 2.5
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
Vulnerabilidad de salto de directorio en Spark 2.5 permite a atacantes remotos leer archivos arbitrarios a través de un .. (punto punto) en la URI.
A path traversal issue was found in Spark version 2.5 and potentially earlier versions. The vulnerability resides in the functionality to serve static files where there's no protection against directory traversal attacks. This could allow attackers access to private files including sensitive data.
Red Hat JBoss Fuse, based on Apache ServiceMix, provides a small-footprint, flexible, open source enterprise service bus and integration platform. Red Hat JBoss A-MQ, based on Apache ActiveMQ, is a standards compliant messaging system that is tailored for use in mission critical applications. This patch is an update to Red Hat JBoss Fuse 6.3 and Red Hat JBoss A-MQ 6.3. It includes bug fixes and enhancements, which are documented in the readme.txt file included with the patch files. Multiple security issues have been addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-04 CVE Reserved
- 2016-11-04 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/94218 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://seclists.org/fulldisclosure/2016/Nov/13 | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://github.com/perwendel/spark/issues/700 | 2018-01-05 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2017:0868 | 2018-01-05 | |
https://access.redhat.com/security/cve/CVE-2016-9177 | 2017-04-03 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1393607 | 2017-04-03 |