First published: Sat Feb 18 2012(Updated: )
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ivanti LANDESK Management Suite | =9.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1196 is rated as a critical severity vulnerability due to its potential to allow remote file deletion.
To fix CVE-2012-1196, upgrade to a later version of Lenovo ThinkManagement Console that addresses this vulnerability.
CVE-2012-1196 allows remote attackers to exploit directory traversal to delete arbitrary files on the server.
CVE-2012-1196 affects Lenovo ThinkManagement Console version 9.0.3.
Failure to mitigate CVE-2012-1196 could lead to critical information loss and unauthorized access to sensitive files.