CVE-2010-4622: Path Traversal
Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 6.1.1 before 6.1.1-TIV-AWS-FP0001 on AIX allows remote attackers to read arbitrary files via a %uff0e%uff0e (encoded dot dot) in a URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4622?
CVE-2010-4622 is considered a high severity vulnerability due to its potential to allow remote attackers to read arbitrary files.
How do I fix CVE-2010-4622?
To fix CVE-2010-4622, upgrade IBM Tivoli Access Manager for e-business to version 6.1.1-TIV-AWS-FP0001 or later.
Who is affected by CVE-2010-4622?
CVE-2010-4622 affects IBM Tivoli Access Manager for e-business version 6.1.1 running on AIX.
What attack vector is used in CVE-2010-4622?
The attack vector for CVE-2010-4622 involves sending a specially crafted URI with encoded directory traversal characters.
What can attackers gain from exploiting CVE-2010-4622?
Exploiting CVE-2010-4622 can allow attackers to read sensitive and arbitrary files on the server.