CVE-2012-1089: Path Traversal
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1089?
CVE-2012-1089 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2012-1089?
To fix CVE-2012-1089, upgrade Apache Wicket to versions 1.4.20 or 1.5.5 or later.
What versions of Apache Wicket are affected by CVE-2012-1089?
Apache Wicket versions 1.4.x before 1.4.20 and 1.5.x before 1.5.5 are affected by CVE-2012-1089.
What kind of attack can exploit CVE-2012-1089?
CVE-2012-1089 can be exploited by remote attackers to conduct directory traversal attacks, allowing access to sensitive files.
Is CVE-2012-1089 specific to a certain type of application?
Yes, CVE-2012-1089 specifically affects web applications utilizing Apache Wicket framework.