5

CVE-2012-4834

Directory traversal vulnerability in LayerLoader.jsp in the theme component in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF19 and 8.0 before CF03 allows remote attackers to read arbitrary files via a crafted URI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Portal Version 7.0.0.1
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf002
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf003
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf004
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf005
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf006
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf007
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf008
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf009
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf010
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf011
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf012
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf013
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf014
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf015
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf016
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf017
Ibm ≫ Websphere Portal Version 7.0.0.1 Update cf018
Ibm ≫ Websphere Portal Version 7.0.0.2
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf002
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf003
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf004
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf005
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf006
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf007
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf008
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf009
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf010
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf011
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf012
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf013
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf014
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf015
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf016
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf017
Ibm ≫ Websphere Portal Version 7.0.0.2 Update cf018
Ibm ≫ Websphere Portal Version 8.0.0.0
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf01
Ibm ≫ Websphere Portal Version 8.0.0.0 Update cf02
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.13% 0.862
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://secunia.com/advisories/51281
Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg1PM76354
Vendor Advisory
http://www.ibm.com/connections/blogs/PSIRT/entry/security_vulnerability_in_theme_component_for_websphere_portal_versions_7_0_0_x_and_8_0_cve2012_48344
Patch
Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=swg21617713
Patch
Vendor Advisory
http://www.ibm.com/support/docview.wss?uid=swg24033155
Patch
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/78914
Third Party Advisory
VDB Entry