First published: Sun Apr 24 2005(Updated: )
By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM iSeries AS/400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1238 has been classified as a high severity vulnerability due to its potential for sensitive data exposure.
To remediate CVE-2005-1238, restrict access to the FTP server and implement proper permissions to prevent unauthorized file access.
The vulnerability CVE-2005-1238 affects IBM iSeries AS/400 systems with the built-in FTP server.
CVE-2005-1238 could allow an attacker to read or write arbitrary files on the system, including sensitive database files.
There is no specific patch for CVE-2005-1238; instead, best security practices recommend configuring the FTP server appropriately.