PT-2016-6759 · Ibm+1 · Ibm Tivoli Lightweight Infrastructure+5
Published
2016-09-22
·
Updated
2017-07-30
·
CVE-2016-6038
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Lightweight Infrastructure (LWI) versions in AIX 5.3, 6.1, and 7.1
IBM System Director Console for AIX (pconsole) (affected versions not specified)
Web Based System Management Remote Client (WebSM Remote) (affected versions not specified)
Description
A directory traversal issue in the Eclipse Help component allows remote attackers to read arbitrary files via a crafted URL. This issue affects remote authenticated users.
Recommendations
For IBM Tivoli Lightweight Infrastructure (LWI) in AIX 5.3, 6.1, and 7.1, restrict access to the Eclipse Help component until a fix is available.
For IBM System Director Console for AIX (pconsole), consider disabling remote access to the Eclipse Help component as a temporary workaround.
For Web Based System Management Remote Client (WebSM Remote), avoid using the vulnerable Eclipse Help component until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aix
Eclipse Help
Ibm Aix
Ibm System Director Console For Aix
Ibm Tivoli Lightweight Infrastructure
Web Based System Management Remote Client