HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2121
Reference (s):
- BID:74583
- URL: http://www.securityfocus.com/bid/74583
- HP:HPSBGN03328
- URL: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04657310
- HP:SSRT101932