First published: Tue Jul 03 2012(Updated: )
Directory traversal vulnerability in the Dojo module in IBM WebSphere Portal 7.0.0.1 and 7.0.0.2 before CF14, and 8.0, allows remote attackers to read arbitrary files via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Portal | =7.0.0.1 | |
IBM WebSphere Portal | =7.0.0.2 | |
IBM WebSphere Portal | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2181 is classified as a medium severity vulnerability due to its ability to allow unauthorized access to sensitive files.
To fix CVE-2012-2181, upgrade to IBM WebSphere Portal versions 7.0.0.3 or 8.0.0.1 or later where the vulnerability has been addressed.
The affected systems include IBM WebSphere Portal versions 7.0.0.1, 7.0.0.2, and 8.0.
Yes, CVE-2012-2181 can be exploited remotely by attackers through crafted URLs.
CVE-2012-2181 can lead to unauthorized disclosure of sensitive information stored on the affected systems.