IBM Tealeaf Customer Experience CVE-2017-1279 Directory Traversal Vulnerability
BID:102887
Info
IBM Tealeaf Customer Experience CVE-2017-1279 Directory Traversal Vulnerability
| Bugtraq ID: | 102887 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-1279 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2017 12:00AM |
| Updated: | Jul 21 2017 12:00AM |
| Credit: | Ugur Cihan Koc |
| Vulnerable: |
IBM Tealeaf Customer Experience 9.0.2 IBM Tealeaf Customer Experience 8.8 IBM Tealeaf Customer Experience 8.7 |
| Not Vulnerable: | |
Discussion
IBM Tealeaf Customer Experience CVE-2017-1279 Directory Traversal Vulnerability
IBM Tealeaf Customer Experience is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information or to access files outside of the restricted directory to obtain sensitive information and perform other attacks.
IBM Tealeaf Customer Experience versions 8.7, 8.8 and 9.0.2 are vulnerable.
IBM Tealeaf Customer Experience is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue using directory-traversal characters ('../') to access or read arbitrary files that contain sensitive information or to access files outside of the restricted directory to obtain sensitive information and perform other attacks.
IBM Tealeaf Customer Experience versions 8.7, 8.8 and 9.0.2 are vulnerable.
Solution / Fix
IBM Tealeaf Customer Experience CVE-2017-1279 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.