CVE-2017-10949: Dell Storage Manager 2016

High severity, CVSS 7.5. EPSS: 5.4% chance of exploitation in the next 30 days.

Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.

Affected products

  • Dell Storage Manager 2016: version r2.1 only

Published 2017-08-04. Last modified 2026-06-17.