Описание
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
Ссылки
- Vendor Advisory
- PatchVendor Advisory
- Exploit
- PatchVendor Advisory
- Vendor Advisory
- PatchVendor Advisory
- Exploit
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.20.3 (включая)
Одновременно
Одно из
cpe:2.3:a:ibm:director:*:service_update_1:*:*:*:*:*:*
cpe:2.3:a:ibm:director:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:4.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:4.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:4.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:4.20:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:4.21:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:4.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:5.10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:5.10.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:5.10.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:5.10.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:5.20.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:5.20.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:director:5.20.2:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*
EPSS
Процентиль: 98%
0.63557
Средний
6.8 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
почти 4 года назад
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.
EPSS
Процентиль: 98%
0.63557
Средний
6.8 Medium
CVSS2
Дефекты
CWE-22