First published: Wed Apr 30 2008(Updated: )
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) CompactSave and (2) SaveSession method in one control, and the (3) saveRecordedExploreToFile method in a different control. NOTE: this can be leveraged for code execution by writing to a Startup folder.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security AppScan | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2015 is rated as a medium severity vulnerability due to its risk of file manipulation.
To fix CVE-2008-2015, upgrade to a version of WatchFire AppScan that is patched against this vulnerability.
CVE-2008-2015 allows remote attackers to execute path traversal attacks, potentially leading to unauthorized file creation or overwriting.
CVE-2008-2015 specifically affects WatchFire AppScan version 7.0.
The CompactSave and SaveSession methods in specific ActiveX controls are vulnerable in CVE-2008-2015.