Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5001

Опубликовано: 01 мар. 2023
Источник: nvd
CVSS3: 4.3
CVSS3: 7.5
EPSS Низкий

Описание

IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:financial_transaction_manager:*:*:*:*:*:*:*:*
Версия от 3.2.0 (включая) до 3.2.7 (включая)

EPSS

Процентиль: 24%
0.00083
Низкий

4.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 7.5
github
почти 3 года назад

IBM Financial Transaction Manager 3.2.0 through 3.2.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 192953.

EPSS

Процентиль: 24%
0.00083
Низкий

4.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22
CWE-22