IBM WebSphere Portal Dojo Module Directory Traversal Vulnerability
BID:54349
Info
IBM WebSphere Portal Dojo Module Directory Traversal Vulnerability
| Bugtraq ID: | 54349 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2181 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2012 12:00AM |
| Updated: | Jul 09 2012 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Websphere Portal 7.0.0.1 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Portal Dojo Module Directory Traversal Vulnerability
IBM WebSphere Portal is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
IBM WebSphere Portal versions 7.0.0.x and 8.0 are vulnerable.
IBM WebSphere Portal is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
IBM WebSphere Portal versions 7.0.0.x and 8.0 are vulnerable.
Exploit / POC
IBM WebSphere Portal Dojo Module Directory Traversal Vulnerability
An attacker can exploit the issue through a browser.
An attacker can exploit the issue through a browser.
Solution / Fix
IBM WebSphere Portal Dojo Module Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM WebSphere Portal Dojo Module Directory Traversal Vulnerability
References:
References: