CVE-2017-16599 is a path traversal vulnerability affecting NetGain Systems Enterprise Manager 7.2.730 build 1034, allowing authenticated remote attackers to delete arbitrary files. The vulnerability, residing in the sample_jsp servlet on TCP port 8081, stems from insufficient validation of the 'type' parameter during file operations, which can be combined with other vulnerabilities for code execution. Rated 6.5 MEDIUM, it has a low attack complexity and requires authentication, though the authentication mechanism can be bypassed. There is no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.2.730CPE matchmatch criteria | cpe:2.3:a:netgain-systems:enterprise_manager:7.2.730:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.