PT-2005-3509 · Autonomy+1 · Autonomy Keyview Sdk+1
Published
2005-12-31
·
Updated
2018-10-19
·
CVE-2005-2619
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Autonomy KeyView SDK versions prior to 9.2.0
Lotus Notes versions 6.5.4 and 7.0
Description
The issue allows remote attackers to delete arbitrary files by exploiting a directory traversal vulnerability. This can be achieved through a ZIP, UUE, or TAR archive containing a .. (dot dot) in the filename, which is not properly handled when generating a preview.
Recommendations
For Autonomy KeyView SDK versions prior to 9.2.0, update to version 9.2.0 or later.
For Lotus Notes versions 6.5.4 and 7.0, consider restricting access to the KeyView SDK functionality until a patch or update is available.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autonomy Keyview Sdk
Lotus Notes