IBM Tivoli SecureWay Policy Director Directory Traversal Vulnerability
BID:3080
Info
IBM Tivoli SecureWay Policy Director Directory Traversal Vulnerability
| Bugtraq ID: | 3080 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2001 12:00AM |
| Updated: | Jul 23 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by [email protected] (Patrik Karlsson) on July 23, 2001. |
| Vulnerable: |
IBM Tivoli SecureWay Policy Director 3.7.1 IBM Tivoli SecureWay Policy Director 3.7 IBM Tivoli SecureWay Policy Director 3.6 IBM Tivoli SecureWay Policy Director 3.0.1 |
| Not Vulnerable: | |
Discussion
IBM Tivoli SecureWay Policy Director Directory Traversal Vulnerability
It is possible for a remote user to traverse the directories of a host running IBM Tivoli SecureWay Policy Director. Submitting a specially crafted URL using hex encoded 'double dot' sequences will reveal arbitrary directories. In addition to revealing directories, this vulnerability could enable a user to obtain the contents of files readable by the webserver user.
It is possible for a remote user to traverse the directories of a host running IBM Tivoli SecureWay Policy Director. Submitting a specially crafted URL using hex encoded 'double dot' sequences will reveal arbitrary directories. In addition to revealing directories, this vulnerability could enable a user to obtain the contents of files readable by the webserver user.
Exploit / POC
IBM Tivoli SecureWay Policy Director Directory Traversal Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.