First published: Fri Jun 18 2010(Updated: )
Directory traversal vulnerability in the getEntry method in the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console (aka Access Management Console) in Novell Access Manager 3.1 before 3.1.2-281 on Windows allows remote attackers to create arbitrary files with any contents, and consequently execute arbitrary code, via a .. (dot dot) in a parameter, aka ZDI-CAN-678.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Access Manager | =3.1 | |
Novell Access Manager | =3.1-sp1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0284 is considered to have a medium severity rating due to its directory traversal vulnerability that can lead to unauthorized file creation.
To fix CVE-2010-0284, you should upgrade to Novell Access Manager version 3.1.2-281 or later.
CVE-2010-0284 affects Novell Access Manager versions 3.1 and 3.1-sp1 running on Windows systems.
Yes, CVE-2010-0284 can be exploited remotely by attackers to create arbitrary files.
The vulnerability in CVE-2010-0284 is caused by a directory traversal flaw in the getEntry method of the PortalModuleInstallManager component.