Описание
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172.
Ссылки
- Broken LinkThird Party AdvisoryVDB Entry
- VDB EntryVendor Advisory
- Broken LinkPatchVendor Advisory
- Broken LinkThird Party AdvisoryVDB Entry
- VDB EntryVendor Advisory
- Broken LinkPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:ibm:campaign:9.1.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:campaign:10.1:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00361
Низкий
4.3 Medium
CVSS3
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 4.3
github
больше 3 лет назад
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 162172.
EPSS
Процентиль: 58%
0.00361
Низкий
4.3 Medium
CVSS3
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22