IBM Tealeaf CX Unspecified Local File Include Vulnerability
BID:65987
Info
IBM Tealeaf CX Unspecified Local File Include Vulnerability
| Bugtraq ID: | 65987 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-6720 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2014 12:00AM |
| Updated: | Mar 05 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Tealeaf CX Unspecified Local File Include Vulnerability
IBM Tealeaf CX is prone to an unspecified local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability using directory-traversal strings to view local files within the context of the web server process. Information harvested may aid in further attacks.
IBM Tealeaf 7.1, 7.2 and 8.0 through 8.8 are vulnerable.
IBM Tealeaf CX is prone to an unspecified local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability using directory-traversal strings to view local files within the context of the web server process. Information harvested may aid in further attacks.
IBM Tealeaf 7.1, 7.2 and 8.0 through 8.8 are vulnerable.
Exploit / POC
IBM Tealeaf CX Unspecified Local File Include Vulnerability
Attackers can use a browser and readily available tools to exploit this issue.
Attackers can use a browser and readily available tools to exploit this issue.
Solution / Fix
IBM Tealeaf CX Unspecified Local File Include Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Tealeaf CX Unspecified Local File Include Vulnerability
References:
References: