VID |
22875 |
Severity |
30 |
Port |
8880, ... |
Protocol |
TCP |
Class |
WWW |
Detailed Description |
The version of IBM WebSphere Application Server running on the remote host is 7.0 prior to 7.0.0.45. It is, therefore, affected by a directory traversal vulnerability in the admin console. An authenticated, remote attacker can exploit this, by sending a URI that contains directory traversal characters, to disclose the contents of files located outside of the server's restricted path.
* References : https://www-01.ibm.com/support/docview.wss?uid=ibm10729521
* Platforms Affected: IBM WebSphere Application Server 7.0.x prior to 7.0.0.45 Any operating system Any version |
Recommendation |
Upgrade to the latest version of IBM WebSphere Application Server 7.0.0.45 or later, available from the IBM Support & downloads Web site at http://www-01.ibm.com/support/docview.wss?rs=180&uid=swg27004980 |
Related URL |
CVE-2018-1770 (CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|