First published: Tue Sep 14 2010(Updated: )
Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object Reference vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Proventia Network Mail Security System Virtual Appliance | ||
Ibm Proventia Network Mail Security System Virtual Appliance Firmware | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0154 is classified as a medium severity directory traversal vulnerability.
To fix CVE-2010-0154, upgrade the firmware of the IBM Proventia Network Mail Security System to version 2.5 or later.
CVE-2010-0154 affects users of IBM Proventia Network Mail Security System appliances with firmware versions prior to 2.5.
CVE-2010-0154 is a directory traversal vulnerability that allows remote authenticated users to read arbitrary files.
The impact of CVE-2010-0154 includes unauthorized access to sensitive files on the server due to improper validation of user input.