First published: Sat Feb 01 2014(Updated: )
Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathname.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Financial Transaction Manager | =2.0.0.0 | |
Ibm Financial Transaction Manager | =2.0.0.1 | |
Ibm Financial Transaction Manager | =2.0.0.2 | |
Ibm Financial Transaction Manager | =2.1.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0830 has a medium severity rating as it allows remote authenticated users to exploit file access vulnerabilities.
To fix CVE-2014-0830, upgrade IBM Financial Transaction Manager to version 2.0.0.3 or 2.1.0.1 or later.
CVE-2014-0830 affects users of IBM Financial Transaction Manager versions 2.0.0.0 to 2.0.0.2 and 2.1.0.0.
CVE-2014-0830 is a directory traversal vulnerability that allows unauthorized file access.
Yes, CVE-2014-0830 can allow attackers to read arbitrary files, potentially exposing sensitive information.