CVE-2014-6158
Summary
| CVE | CVE-2014-6158 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-10 02:59:00 UTC |
| Updated | 2017-09-08 01:29:00 UTC |
| Description | Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 before 2.0.0.1 and Workload Deployer 3.1.0.7 before IF5 allow remote authenticated users to execute arbitrary code via a (1) Script Package, (2) Add-On, or (3) Emergency Fixes component. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Pureapplication System | 1.0.0.0 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.1 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.2 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.3 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.0 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.1 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.2 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.3 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.4 | All | All | All |
| Application | Ibm | Pureapplication System | 2.0.0.0 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.0 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.1 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.2 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.3 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.0 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.1 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.2 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.3 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.4 | All | All | All |
| Application | Ibm | Pureapplication System | 2.0.0.0 | All | All | All |
| Application | Ibm | Workload Deployer | 3.1.0.7 | All | All | All |
| Application | Ibm | Workload Deployer | 3.1.0.7 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: File path traversal vulnerabilities affect IBM PureApplication System (CVE-2014-6158) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| Security Bulletin: File path traversal vulnerabilities affect IBM Workload Deployer (CVE-2014-6158) | CONFIRM | www-01.ibm.com | Patch, Vendor Advisory |
| About Secunia Research | Flexera | SECUNIA | secunia.com | |
| About Secunia Research | Flexera | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.