QID 375679
Date Published: 2021-07-12
QID 375679: IBM WebSphere Application Server Directory Traversal Vulnerability (6427873)
WebSphere Application Server is vulnerable to a directory traversal vulnerability.When application security is disabled and JAX-RPC applications are present, an attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary xml files on the system.
Affected Versions:
WebSphere Application Server V9.0.0.0 through 9.0.5.6
WebSphere Application Server V8.5.0.0 through 8.5.5.19
WebSphere Application Server V8.0.0.0 through 8.0.0.15
WebSphere Application Server V7.0.0.0 through 7.0.0.45
QID Detection Logic (Authenticated):
This QID checks for the vulnerable version of IBM WebSphere Application Server and checks if the patches are installed or not.
QID Detection Logic (Unauthenticated):
This QID matches vulnerable versions via the GIOP banner.
An attacker could allow a remote attacker to traverse directories on the system.
- 6427873 -
www.ibm.com/support/pages/node/6427873
CVEs related to QID 375679
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| IBM Websphere(6427873) |
|