Описание
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
8 High
CVSS3
Дефекты
Связанные уязвимости
AMD: CVE-2025-36357 Transient Scheduler Attack in L1 Data Queue
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or write arbitrary files on the system.
Уязвимость системы очереди AMD Store Queue операционных систем Windows, позволяющая нарушителю получить доступ к конфиденциальной информации
EPSS
8 High
CVSS3