Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to openwsman server.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libwsman1Upgrade openwsman-clientUpgrade openwsman-serverUpgrade openwsman-pythonUpgrade libwsman-develUpgrade openwsman-perlUpgrade openwsman-debuginfoUpgrade openwsman-ruby | Apr 27, 2020 | Mar 14, 2019 |
| Centos_linux | — | Upgrade openwsman-perl-debuginfoUpgrade openwsman-clientUpgrade openwsman-serverUpgrade openwsman-rubyUpgrade rubygem-openwsman-debuginfoUpgrade openwsman-server-debuginfoUpgrade openwsman-debugsourceUpgrade libwsman-develUpgrade openwsman-python3-debuginfoUpgrade openwsman-debuginfoUpgrade openwsman-client-debuginfoUpgrade libwsman1Upgrade libwsman1-debuginfoUpgrade openwsman-perlUpgrade openwsman-python3Upgrade openwsman-python | May 1, 2019 | Mar 14, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libwsman1Upgrade openwsman-clientUpgrade openwsman-server | May 7, 2019 | Mar 14, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openwsman-clientUpgrade libwsman1Upgrade openwsman-server | May 7, 2019 | Mar 14, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openwsman-clientUpgrade openwsman-pythonUpgrade openwsman-serverUpgrade libwsman1 | May 7, 2019 | Mar 14, 2019 |
| Oracle_linux | — | Upgrade openwsman-python3Upgrade libwsman1Upgrade openwsman-pythonUpgrade openwsman-perlUpgrade openwsman-clientUpgrade libwsman-develUpgrade openwsman-serverUpgrade openwsman-ruby | Jul 21, 2020 | Mar 12, 2019 |
| Redhat_linux | — | No solution existsUpgrade libwsman1-debuginfoUpgrade openwsman-serverUpgrade openwsman-clientUpgrade libwsman-develUpgrade openwsman-debuginfoUpgrade openwsman-debugsourceUpgrade openwsman-python3-debuginfoUpgrade openwsman-client-debuginfoUpgrade rubygem-openwsman-debuginfoUpgrade openwsman-server-debuginfoUpgrade libwsman1Upgrade openwsman-perl-debuginfoUpgrade openwsman-python3 | Mar 27, 2019 | Mar 14, 2019 |
| Suse | — | Upgrade openwsman-pythonUpgrade openwsman-ruby-docsUpgrade libwsman-develUpgrade libwsman_clientpp1Upgrade libwsman_clientpp-develUpgrade openwsman-perlUpgrade python3-openwsmanUpgrade libwsman3Upgrade openwsman-clientUpgrade openwsman-serverUpgrade openwsman-rubyUpgrade openwsman-server-plugin-rubyUpgrade libwsman1Upgrade winrsUpgrade openwsman-java | Mar 19, 2019 | Mar 14, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 14, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub