Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-2206

Опубликовано: 17 авг. 2012
Источник: nvd
CVSS2: 3.5
EPSS Низкий

Описание

The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ibm:websphere_mq:7.0:*:file_transfer:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:7.0.0.1:*:file_transfer:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:7.0.1.0:*:file_transfer:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:7.0.2.0:*:file_transfer:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:7.0.2.2:*:file_transfer:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:7.0.4:*:file_transfer:*:*:*:*:*
cpe:2.3:a:ibm:websphere_mq:7.0.4.0:*:file_transfer:*:*:*:*:*

EPSS

Процентиль: 92%
0.07716
Низкий

3.5 Low

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field to the /transfer URI.

EPSS

Процентиль: 92%
0.07716
Низкий

3.5 Low

CVSS2

Дефекты

CWE-264