Korean
<< Back
VID 22875
Severity 30
Port 8880, ...
Protocol TCP
Class WWW
Detailed Description The version of IBM WebSphere Application Server running on the remote host is 7.0 prior to 7.0.0.45. It is, therefore, affected by a directory traversal vulnerability in the admin console.
An authenticated, remote attacker can exploit this, by sending a URI that contains directory traversal characters, to disclose the contents of files located outside of the server's restricted path.

* References :
https://www-01.ibm.com/support/docview.wss?uid=ibm10729521

* Platforms Affected:
IBM WebSphere Application Server 7.0.x prior to 7.0.0.45
Any operating system Any version
Recommendation Upgrade to the latest version of IBM WebSphere Application Server 7.0.0.45 or later, available from the IBM Support & downloads Web site at http://www-01.ibm.com/support/docview.wss?rs=180&uid=swg27004980
Related URL CVE-2018-1770 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)