Synopsis
A web application running on the remote host is affected by a file deletion vulnerability.
Description
The SonicWALL Global Management System (GMS) / Analyzer running on the remote host is affected by a file deletion vulnerability within the sgms web application due to the failure to validate user input to the ChartDisplayServlet servlet. An unauthenticated, remote attacker can exploit this issue to retrieve and delete files for the sgms web application.
Note that GMS / Analyzer is reportedly affected by other vulnerabilities as well; however, this plugin has not tested for these.
Solution
Upgrade to SonicWALL Global Management System (GMS) / Analyzer version 8.3 or later.
Plugin Details
File Name: sonicwall_gms_sgms_webapp_file_deletion.nasl
Supported Sensors: Nessus
Vulnerability Information
CPE: cpe:/a:sonicwall:global_management_system, cpe:/a:sonicwall:analyzer
Required KB Items: installed_sw/sonicwall_universal_management_suite
Patch Publication Date: 3/1/2017