CVE-2012-1196: Path Traversal
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1196?
CVE-2012-1196 is rated as a critical severity vulnerability due to its potential to allow remote file deletion.
How do I fix CVE-2012-1196?
To fix CVE-2012-1196, upgrade to a later version of Lenovo ThinkManagement Console that addresses this vulnerability.
What type of attack is possible with CVE-2012-1196?
CVE-2012-1196 allows remote attackers to exploit directory traversal to delete arbitrary files on the server.
Which software is affected by CVE-2012-1196?
CVE-2012-1196 affects Lenovo ThinkManagement Console version 9.0.3.
What is the impact of not mitigating CVE-2012-1196?
Failure to mitigate CVE-2012-1196 could lead to critical information loss and unauthorized access to sensitive files.