Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to openwsman server.
{
"binaries": [
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "libopenwsman-dev"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "libopenwsman1"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "libwsman-client2"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "libwsman-clientpp-dev"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "libwsman-clientpp1"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "libwsman-curl-client-transport1"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "libwsman-server1"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "libwsman1"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "openwsman"
},
{
"binary_version": "2.4.7-0ubuntu2",
"binary_name": "python-openwsman"
}
]
}{
"binaries": [
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "libopenwsman-dev"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "libopenwsman1"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "libwsman-client4"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "libwsman-clientpp-dev"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "libwsman-clientpp1"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "libwsman-curl-client-transport1"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "libwsman-server1"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "libwsman1"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "openwsman"
},
{
"binary_version": "2.6.5-0ubuntu3",
"binary_name": "python-openwsman"
}
]
}{
"binaries": [
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "libopenwsman-dev"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "libopenwsman1"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "libwsman-client4"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "libwsman-clientpp-dev"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "libwsman-clientpp1"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "libwsman-curl-client-transport1"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "libwsman-server1"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "libwsman1"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "openwsman"
},
{
"binary_version": "2.6.5-0ubuntu5",
"binary_name": "python-openwsman"
}
]
}{
"binaries": [
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "libopenwsman-dev"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "libopenwsman1"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "libwsman-client4"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "libwsman-clientpp-dev"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "libwsman-clientpp1"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "libwsman-curl-client-transport1"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "libwsman-server1"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "libwsman1"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "openwsman"
},
{
"binary_version": "2.6.5-0ubuntu6",
"binary_name": "python-openwsman"
}
]
}{
"binaries": [
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libopenwsman-dev"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libopenwsman1"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-client4t64"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-clientpp-dev"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-clientpp1t64"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-curl-client-transport1"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-server1t64"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman1t64"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "openwsman"
}
]
}{
"binaries": [
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libopenwsman-dev"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libopenwsman1"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-client4t64"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-clientpp-dev"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-clientpp1t64"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-curl-client-transport1"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman-server1t64"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "libwsman1t64"
},
{
"binary_version": "2.6.5-0ubuntu15",
"binary_name": "openwsman"
}
]
}{
"binaries": [
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "libopenwsman-dev"
},
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "libopenwsman1"
},
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "libwsman-client4t64"
},
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "libwsman-clientpp-dev"
},
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "libwsman-clientpp1t64"
},
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "libwsman-curl-client-transport1"
},
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "libwsman-server1t64"
},
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "libwsman1t64"
},
{
"binary_version": "2.6.5-0ubuntu16",
"binary_name": "openwsman"
}
]
}