IBM WebSphere Application Server CVE-2013-0544 Directory Traversal Vulnerability
BID:59250
Info
IBM WebSphere Application Server CVE-2013-0544 Directory Traversal Vulnerability
| Bugtraq ID: | 59250 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0544 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2013 12:00AM |
| Updated: | Mar 19 2015 08:27AM |
| Credit: | Craig Young |
| Vulnerable: |
IBM Websphere Application Server 8.0 2 IBM Websphere Application Server 7.0 21 IBM Websphere Application Server 7.0 .9 IBM Websphere Application Server 7.0 .8 IBM Websphere Application Server 7.0 .2 IBM Websphere Application Server 7.0 .12 IBM Websphere Application Server 7.0 .11 IBM Websphere Application Server 6.1 41 IBM Websphere Application Server 6.1 .9 IBM Websphere Application Server 6.1 .8 IBM Websphere Application Server 6.1 .7 IBM Websphere Application Server 6.1 .6 IBM Websphere Application Server 6.1 .5 IBM Websphere Application Server 6.1 .4 IBM Websphere Application Server 6.1 .33 IBM Websphere Application Server 6.1 .32 IBM Websphere Application Server 6.1 .3 IBM Websphere Application Server 6.1 .25 IBM Websphere Application Server 6.1 .23 IBM Websphere Application Server 6.1 .22 IBM Websphere Application Server 6.1 .21 IBM Websphere Application Server 6.1 .20 IBM Websphere Application Server 6.1 .2 IBM Websphere Application Server 6.1 .19 IBM Websphere Application Server 6.1 .18 IBM Websphere Application Server 6.1 .17 IBM Websphere Application Server 6.1 .15 IBM Websphere Application Server 6.1 .14 IBM Websphere Application Server 6.1 .13 IBM Websphere Application Server 6.1 .12 IBM Websphere Application Server 6.1 .11 IBM Websphere Application Server 6.1 .10 IBM Websphere Application Server 6.1 .1 IBM Websphere Application Server 8.5.0.1 IBM Websphere Application Server 8.5.0.0 IBM Websphere Application Server 8.5 IBM Websphere Application Server 8.0.0.5 IBM Websphere Application Server 8.0.0.4 IBM Websphere Application Server 8.0.0.3 IBM Websphere Application Server 8.0.0.1 IBM Websphere Application Server 8.0 IBM Websphere Application Server 7.0.0.7 IBM Websphere Application Server 7.0.0.6 IBM Websphere Application Server 7.0.0.5 IBM Websphere Application Server 7.0.0.4 IBM Websphere Application Server 7.0.0.27 IBM Websphere Application Server 7.0.0.25 IBM Websphere Application Server 7.0.0.23 IBM Websphere Application Server 7.0.0.19 IBM Websphere Application Server 7.0.0.17 IBM Websphere Application Server 7.0.0.15 IBM Websphere Application Server 7.0.0.14 IBM Websphere Application Server 7.0.0.13 IBM Websphere Application Server 7.0.0.1 IBM Websphere Application Server 7.0 IBM Websphere Application Server 6.1.0.45 IBM Websphere Application Server 6.1.0.43 IBM Websphere Application Server 6.1.0.39 IBM Websphere Application Server 6.1.0.37 IBM Websphere Application Server 6.1.0.35 IBM Websphere Application Server 6.1.0.34 IBM Websphere Application Server 6.1.0.31 IBM Websphere Application Server 6.1.0.29 IBM Websphere Application Server 6.1.0.27 IBM Websphere Application Server 6.1 |
| Not Vulnerable: |
IBM Websphere Application Server 7.0 29 IBM Websphere Application Server 8.5.0.2 IBM Websphere Application Server 8.0.0.6 IBM Websphere Application Server 6.1.0.47 |
Discussion
IBM WebSphere Application Server CVE-2013-0544 Directory Traversal Vulnerability
IBM WebSphere Application Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to gain access to arbitrary files. Information harvested may aid in launching further attacks.
The following IBM WebSphere Application Server versions are vulnerable:
IBM WebSphere Application Server versions 8.5 through 8.5.0.1
IBM WebSphere Application Server versions 8.0 through 8.0.0.5
IBM WebSphere Application Server versions 7.0 through 7.0.0.27
IBM WebSphere Application Server versions 6.1 through 6.1.0.45
IBM WebSphere Application Server is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to gain access to arbitrary files. Information harvested may aid in launching further attacks.
The following IBM WebSphere Application Server versions are vulnerable:
IBM WebSphere Application Server versions 8.5 through 8.5.0.1
IBM WebSphere Application Server versions 8.0 through 8.0.0.5
IBM WebSphere Application Server versions 7.0 through 7.0.0.27
IBM WebSphere Application Server versions 6.1 through 6.1.0.45
Solution / Fix
IBM WebSphere Application Server CVE-2013-0544 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM WebSphere Application Server CVE-2013-0544 Directory Traversal Vulnerability
References:
References: