IBM InfoSphere Optim Performance Manager CVE-2013-2979 Unspecified Directory Traversal Vulnerability
BID:61948
Info
IBM InfoSphere Optim Performance Manager CVE-2013-2979 Unspecified Directory Traversal Vulnerability
| Bugtraq ID: | 61948 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2979 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 21 2013 12:00AM |
| Updated: | Sep 11 2013 12:16PM |
| Credit: | IBM |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM InfoSphere Optim Performance Manager CVE-2013-2979 Unspecified Directory Traversal Vulnerability
IBM InfoSphere Optim Performance Manager is prone to an unspecified directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
IBM InfoSphere Optim Performance Manager is prone to an unspecified directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Exploit / POC
IBM InfoSphere Optim Performance Manager CVE-2013-2979 Unspecified Directory Traversal Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
IBM InfoSphere Optim Performance Manager CVE-2013-2979 Unspecified Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM InfoSphere Optim Performance Manager CVE-2013-2979 Unspecified Directory Traversal Vulnerability
References:
References:
- IBM Homepage (IBM)