PT-2016-6759 · Ibm+1 · Ibm Tivoli Lightweight Infrastructure+5

Published

2016-09-22

·

Updated

2017-07-30

·

CVE-2016-6038

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Tivoli Lightweight Infrastructure (LWI) versions in AIX 5.3, 6.1, and 7.1 IBM System Director Console for AIX (pconsole) (affected versions not specified) Web Based System Management Remote Client (WebSM Remote) (affected versions not specified)
Description A directory traversal issue in the Eclipse Help component allows remote attackers to read arbitrary files via a crafted URL. This issue affects remote authenticated users.
Recommendations For IBM Tivoli Lightweight Infrastructure (LWI) in AIX 5.3, 6.1, and 7.1, restrict access to the Eclipse Help component until a fix is available. For IBM System Director Console for AIX (pconsole), consider disabling remote access to the Eclipse Help component as a temporary workaround. For Web Based System Management Remote Client (WebSM Remote), avoid using the vulnerable Eclipse Help component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-6038

Affected Products

Aix
Eclipse Help
Ibm Aix
Ibm System Director Console For Aix
Ibm Tivoli Lightweight Infrastructure
Web Based System Management Remote Client