First published: Fri Jun 22 2012(Updated: )
Directory traversal vulnerability in the Eclipse Help component in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows remote attackers to discover the locations of files via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Expeditor | =6.1 | |
IBM Expeditor | =6.1.1 | |
IBM Expeditor | =6.2 | |
IBM Expeditor | =6.2.1 | |
IBM Expeditor | =6.2.2 | |
IBM Expeditor | =6.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0186 has a moderate severity level due to its potential to expose file locations via directory traversal.
To fix CVE-2012-0186, upgrade IBM Lotus Expeditor to version 6.2 FP5 or later, which includes the necessary security patches.
CVE-2012-0186 affects IBM Lotus Expeditor versions 6.1.x and 6.2.x prior to 6.2 FP5+Security Pack.
Yes, CVE-2012-0186 can be exploited remotely by attackers through crafted URLs.
CVE-2012-0186 is a directory traversal vulnerability that allows unauthorized file location discovery.