Описание
Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via a crafted internationalization-file URL.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- PatchVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Одно из
Одно из
EPSS
4 Medium
CVSS2
Дефекты
Связанные уязвимости
Directory traversal vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, and 8.5.5 through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via a crafted internationalization-file URL.
Уязвимость сервера приложений WebSphere Application Server, позволяющая нарушителю читать произвольные файлы
Уязвимость системы автоматизации деятельности предприятия Business Process Manager, позволяющая нарушителю читать произвольные файлы
EPSS
4 Medium
CVSS2