PT-2015-6736 · Ibm · Ibm Security Access Manager For Web

Publicado

2015-11-08

·

Atualizado

2016-12-07

·

CVE-2015-4963

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM Security Access Manager for Web versions 7.x before 7.0.0.16 IBM Security Access Manager for Web versions 8.x before 8.0.1.3
Description The issue is related to the mishandling of WebSEAL HTTPTransformation requests, allowing remote attackers to read or write to arbitrary files via unspecified vectors.
Recommendations For IBM Security Access Manager for Web versions 7.x before 7.0.0.16, update to version 7.0.0.16 or later. For IBM Security Access Manager for Web versions 8.x before 8.0.1.3, update to version 8.0.1.3 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-4963

Produtos afetados

Ibm Security Access Manager For Web