IBM Engineering Lifecycle Optimization - Publishing
cpe:2.3:a:ibm:engineering_lifecycle_optimization_publishing:*:*:*:*:*:*:*
- 7.0.3
- 7.0.2
A directory traversal vulnerability has been identified in IBM Engineering Lifecycle Optimization - Publishing versions 7.0.2 and 7.0.3. This vulnerability could allow a remote attacker to traverse directories on the system by sending a specially crafted URL request that includes 'dot dot' sequences. Exploitation of this vulnerability could enable the attacker to view arbitrary files on the system.
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the system. Depending on the contents of the accessed files, there could be potential for modifying configuration files, web content, or libraries, which could facilitate further code injection attacks. Additionally, access to system files, such as the password file in Unix/Linux systems, could be obtained using the application server's account permissions.
Users can upgrade to IBM Engineering Lifecycle Optimization - Publishing version 7.0.3 iFix010 or later, or version 7.0.2 iFix032 or later, to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.