CVE-2012-2181: Path Traversal
Published Jul 3, 2012
·Updated
Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.
Affected Software
3 affected components
IBM WebSphere Portal=7.0.0.1
IBM WebSphere Portal=7.0.0.2
IBM WebSphere Portal=8.0
Event History
Jul 3, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2181?
CVE-2012-2181 is classified as a medium severity vulnerability due to its ability to allow unauthorized access to sensitive files.
2
How do I fix CVE-2012-2181?
To fix CVE-2012-2181, upgrade to IBM WebSphere Portal versions 7.0.0.3 or 8.0.0.1 or later where the vulnerability has been addressed.
3
What systems are affected by CVE-2012-2181?
The affected systems include IBM WebSphere Portal versions 7.0.0.1, 7.0.0.2, and 8.0.
4
Can CVE-2012-2181 be exploited remotely?
Yes, CVE-2012-2181 can be exploited remotely by attackers through crafted URLs.
5
What impact does CVE-2012-2181 have on data security?
CVE-2012-2181 can lead to unauthorized disclosure of sensitive information stored on the affected systems.