Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3v6m-8v49-4vvq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.

EPSS

Процентиль: 43%
0.00207
Низкий

Дефекты

CWE-362

Связанные уязвимости

nvd
около 10 лет назад

Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.

EPSS

Процентиль: 43%
0.00207
Низкий

Дефекты

CWE-362