CVE List

CVE-2021-20354

Critical 7.5

IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 194883.

Published February 18, 2021.

Affected software

Get alerts for IBM Websphere Application Server

Reference links