PT-2015-1417 · Ibm · Websphere Lombardi Edition+2
Published
2015-06-28
·
Updated
2016-12-28
·
CVE-2015-1884
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WebSphere Application Server versions prior to the fixed version
IBM Business Process Manager (BPM) versions 7.5.x through 7.5.1.2
IBM Business Process Manager (BPM) versions 8.0.x through 8.0.1.3
IBM Business Process Manager (BPM) versions 8.5.0 through 8.5.0.1
IBM Business Process Manager (BPM) versions 8.5.5 through 8.5.5.0
WebSphere Lombardi Edition (WLE) versions 7.2 through 7.2.0.5
Description
The issue exists due to incorrect restriction of the directory path name with limited access. Exploitation of this issue may allow a remote attacker to read arbitrary files using a specially crafted URL. This is a directory traversal vulnerability that can be exploited by remote authenticated users via a crafted internationalization-file URL.
Recommendations
For IBM Business Process Manager (BPM) versions 7.5.x through 7.5.1.2, update to a version outside of this range.
For IBM Business Process Manager (BPM) versions 8.0.x through 8.0.1.3, update to a version outside of this range.
For IBM Business Process Manager (BPM) versions 8.5.0 through 8.5.0.1, update to a version outside of this range.
For IBM Business Process Manager (BPM) versions 8.5.5 through 8.5.5.0, update to a version outside of this range.
For WebSphere Lombardi Edition (WLE) versions 7.2 through 7.2.0.5, update to a version outside of this range.
As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Business Process Manager
Ibm Websphere Application Server
Websphere Lombardi Edition