CVE-2013-4054: Path Traversal
Published Mar 2, 2014
·Updated
Directory traversal vulnerability in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.3 allows remote attackers to read arbitrary files via a crafted URI.
Affected Software
3 affected components
IBM WebSphere MQ=7.5
IBM WebSphere MQ=7.5.0.1
IBM WebSphere MQ=7.5.0.2
Event History
Mar 2, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4054?
CVE-2013-4054 has a moderate severity rating due to the potential for unauthorized file access.
2
How do I fix CVE-2013-4054?
To fix CVE-2013-4054, upgrade IBM WebSphere MQ to version 7.5.0.3 or later.
3
What software versions are affected by CVE-2013-4054?
CVE-2013-4054 affects IBM WebSphere MQ versions 7.5, 7.5.0.1, and 7.5.0.2.
4
What type of attack does CVE-2013-4054 enable?
CVE-2013-4054 enables remote attackers to exploit a directory traversal to read arbitrary files on the server.
5
Is CVE-2013-4054 a local or remote vulnerability?
CVE-2013-4054 is a remote vulnerability, allowing attackers to exploit it from a distant location.