First published: Sun Mar 02 2014(Updated: )
Directory traversal vulnerability in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.3 allows remote attackers to read arbitrary files via a crafted URI.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere MQ Appliance | =7.5 | |
IBM WebSphere MQ Appliance | =7.5.0.1 | |
IBM WebSphere MQ Appliance | =7.5.0.2 | |
=7.5 | ||
=7.5.0.1 | ||
=7.5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4054 has a moderate severity rating due to the potential for unauthorized file access.
To fix CVE-2013-4054, upgrade IBM WebSphere MQ to version 7.5.0.3 or later.
CVE-2013-4054 affects IBM WebSphere MQ versions 7.5, 7.5.0.1, and 7.5.0.2.
CVE-2013-4054 enables remote attackers to exploit a directory traversal to read arbitrary files on the server.
CVE-2013-4054 is a remote vulnerability, allowing attackers to exploit it from a distant location.