IBM Security Key Lifecycle Manager CVE-2017-1671 Directory Traversal Vulnerability
BID:102487
CVE-2017-1671 |Info
IBM Security Key Lifecycle Manager CVE-2017-1671 Directory Traversal Vulnerability
| Bugtraq ID: | 102487 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-1671 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2018 12:00AM |
| Updated: | Jan 05 2018 12:00AM |
| Credit: | IBM X-Force Ethical Hacking Team: Ron Craig, Warren Moynihan, Jonathan Fitz-Gerald, John Zuccato, Rodney Ryan, Chris Shepherd, Dmitriy Beryoza |
| Vulnerable: |
IBM Security Key Lifecycle Manager 2.7.0.2 IBM Security Key Lifecycle Manager 2.7.0.0 IBM Security Key Lifecycle Manager 2.7 IBM Security Key Lifecycle Manager 2.6.0.3 IBM Security Key Lifecycle Manager 2.6.0.2 IBM Security Key Lifecycle Manager 2.6.0.1 IBM Security Key Lifecycle Manager 2.6 IBM Security Key Lifecycle Manager 2.5.0.8 IBM Security Key Lifecycle Manager 2.5.0.7 IBM Security Key Lifecycle Manager 2.5.0.1 IBM Security Key Lifecycle Manager 2.5 |
| Not Vulnerable: | |
Discussion
IBM Security Key Lifecycle Manager CVE-2017-1671 Directory Traversal Vulnerability
IBM Security Key Lifecycle Manager is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to view arbitrary files on the system. This may aid in further attacks.
The following products are affected:
IBM Security Key Lifecycle Manager versions 2.5 through 2.5.0.8
IBM Security Key Lifecycle Manager versions 2.6 through 2.6.0.3
IBM Security Key Lifecycle Manager versions 2.7 through 2.7.0.2
IBM Security Key Lifecycle Manager is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to view arbitrary files on the system. This may aid in further attacks.
The following products are affected:
IBM Security Key Lifecycle Manager versions 2.5 through 2.5.0.8
IBM Security Key Lifecycle Manager versions 2.6 through 2.6.0.3
IBM Security Key Lifecycle Manager versions 2.7 through 2.7.0.2
Solution / Fix
IBM Security Key Lifecycle Manager CVE-2017-1671 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.