CVE-2025-7039
Secure Connect Gateway: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2025-7039)
Affected
- NetApp/ActiveIQ Unified Manager
< *..9.13 - NetApp/ActiveIQ Unified Manager
< *..9.14 - NetApp/ActiveIQ Unified Manager
= 9.16..9.16 - Dell/Secure Connect Gateway
< *..5.36.00.16
Fixed in
- NetApp/ActiveIQ Unified Manager
9.13 - NetApp/ActiveIQ Unified Manager
9.14 - Dell/Secure Connect Gateway
5.36.00.16
Description
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
< 5.36.00.16fixed in 5.36.00.169.16< 9.13fixed in 9.13< 9.14fixed in 9.14Metrics
Show all metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →