QID 91839
QID 91839: IBM Integration Bus Node.js Vulnerability (6515532,6516066)
IBM Integration Bus (formerly known ad IBM WebSphere Message Broker) is IBM's integration broker from the WebSphere product family that allows business information to flow between disparate applications across multiple hardware and software platforms.
Affected Products and Versions:
IBM Integration Bus V10.0.0 - V10.0.0.24
QID Detection Logic (Authenticated):
Operating System: Windows
The QID checks if a vulnerable version of IBM Integration Bus and IBM App Connect Enterprise is installed on the system.
Node.js tar module could allow a local attacker to traverse directories on the system, caused by insufficient absolute path sanitization. An attacker could use a specially-crafted tar file containing "dot dot" sequences (/../) to create or overwrite arbitrary files on the system.
- IBM Security Bulletin (6515532) -
www.ibm.com/support/pages/node/6515532 - IBM Security Bulletin (6516066) -
www.ibm.com/support/pages/node/6516066
CVEs related to QID 91839
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6515532 |
|
||
| 6516066 |
|