Description
Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 5.1 before 5.1.0.39-TIV-AWS-IF0040, 6.0 before 6.0.0.25-TIV-AWS-IF0026, 6.1.0 before 6.1.0.5-TIV-AWS-IF0006, and 6.1.1 before 6.1.1-TIV-AWS-FP0001 has unspecified impact and attack vectors.
Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 on AIX allows remote attackers to read arbitrary files via a %uff0e%uff0e (encoded dot dot) in a URI.
Remediation
Update to the latest version of IBM Tivoli Access Manager.
References
Related Vulnerabilities
Oracle Database Server CVE-2007-5514 Vulnerability (CVE-2007-5514)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4431)
PHP Observable Discrepancy Vulnerability (CVE-2024-2408)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17305)