First published: Wed Jul 07 2010(Updated: )
Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, allows remote authenticated users to list arbitrary directories and possibly have unspecified other impact via a .. (dot dot) in the DIR parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Advanced Management Module | <=2.48 | |
Ibm Advanced Management Module | =1.00 | |
Ibm Advanced Management Module | =1.01 | |
Ibm Advanced Management Module | =1.20 | |
Ibm Advanced Management Module | =1.20-f | |
Ibm Advanced Management Module | =1.25 | |
Ibm Advanced Management Module | =1.25-e | |
Ibm Advanced Management Module | =1.25-i | |
Ibm Advanced Management Module | =1.26-b | |
Ibm Advanced Management Module | =1.26-e | |
Ibm Advanced Management Module | =1.26-h | |
Ibm Advanced Management Module | =1.26-i | |
Ibm Advanced Management Module | =1.26-k | |
Ibm Advanced Management Module | =1.28-g | |
Ibm Advanced Management Module | =1.32-d | |
Ibm Advanced Management Module | =1.34-b | |
Ibm Advanced Management Module | =1.34-e | |
Ibm Advanced Management Module | =1.36-d | |
Ibm Advanced Management Module | =1.36-g | |
Ibm Advanced Management Module | =1.36-h | |
Ibm Advanced Management Module | =1.36-k | |
Ibm Advanced Management Module | =1.42-d | |
Ibm Advanced Management Module | =1.42-f | |
Ibm Advanced Management Module | =1.42-i | |
Ibm Advanced Management Module | =1.42-n | |
Ibm Advanced Management Module | =1.42-o | |
Ibm Advanced Management Module | =1.42-t | |
Ibm Advanced Management Module | =2.46-c | |
Ibm Advanced Management Module | =2.46-j | |
Ibm Advanced Management Module | =2.48-c | |
Ibm Advanced Management Module | =2.48-d | |
Ibm Advanced Management Module | =2.48-g | |
Ibm Advanced Management Module | =2.48-n | |
Ibm Advanced Management Module | =2.50-c | |
Ibm Advanced Management Module | =2.50-g | |
Ibm Advanced Management Module | =2.50-k | |
Ibm Advanced Management Module | =2.50-p | |
IBM BladeCenter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2655 is rated as a medium-severity vulnerability due to its potential for directory traversal attacks.
To resolve CVE-2010-2655, upgrade the IBM Advanced Management Module firmware to version 4.7 or later.
CVE-2010-2655 affects IBM Advanced Management Module firmware versions prior to 4.7, including 2.48 and earlier.
CVE-2010-2655 can be exploited by remote authenticated users with the ability to access the vulnerable services.
Exploitation of CVE-2010-2655 may allow attackers to list arbitrary directories and possibly access restricted files.