First published: Sat Jul 19 2014(Updated: )
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0 FP4 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 allows remote authenticated users to read arbitrary files via a crafted UNIX file parameter.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Infosphere Master Data Management Collaboration Server | =10.0 | |
Ibm Infosphere Master Data Management Collaboration Server | =10.1 | |
Ibm Infosphere Master Data Management Collaboration Server | =11.0 | |
IBM InfoSphere Master Data Management Server for Product Information Management | =9.0 | |
IBM InfoSphere Master Data Management Server for Product Information Management | =9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3064 has a medium severity rating due to the potential for unauthorized file access by remote authenticated users.
To fix CVE-2014-3064, upgrade to IBM InfoSphere Master Data Management - Collaborative Edition version 11.0 FP4 or later.
CVE-2014-3064 affects IBM InfoSphere Master Data Management - Collaborative Edition versions 10.0, 10.1, 11.0 prior to FP4, and versions 9.0 and 9.1 of the IBM InfoSphere Master Data Management Server for Product Information Management.
CVE-2014-3064 is a file read vulnerability that allows remote authenticated users to access arbitrary files.
Organizations using the specified versions of IBM InfoSphere Master Data Management products are at risk from CVE-2014-3064.