CVE-2014-6158
Summary
| CVE | CVE-2014-6158 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-10 02:59:26 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Multiple directory traversal vulnerabilities in the file-upload feature in IBM PureApplication System 1.0 before 1.0.0.4 iFix 10, 1.1 before 1.1.0.5, and 2.0 before 2.0.0.1 and Workload Deployer 3.1.0.7 before IF5 allow remote authenticated users to execute arbitrary code via a (1) Script Package, (2) Add-On, or (3) Emergency Fixes component. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:S/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Pureapplication System | 1.0.0.0 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.1 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.2 | All | All | All |
| Application | Ibm | Pureapplication System | 1.0.0.3 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.0 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.1 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.2 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.3 | All | All | All |
| Application | Ibm | Pureapplication System | 1.1.0.4 | All | All | All |
| Application | Ibm | Pureapplication System | 2.0.0.0 | All | All | All |
| Application | Ibm | Workload Deployer | 3.1.0.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: File path traversal vulnerabilities affect IBM Workload Deployer (CVE-2014-6158) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Bulletin: File path traversal vulnerabilities affect IBM PureApplication System (CVE-2014-6158) | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.