CVE-2014-6095: Path Traversal
Published Nov 18, 2014
·Updated
Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to read arbitrary files via unspecified vectors.
Affected Software
4 affected components
IBM Security Identity Manager=6.0.0.0
IBM Security Identity Manager=6.0.0.1
IBM Security Identity Manager=6.0.0.2
IBM Security Identity Manager=6.0.0.3
Event History
Nov 18, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6095?
CVE-2014-6095 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive files.
2
How do I fix CVE-2014-6095?
To fix CVE-2014-6095, upgrade IBM Security Identity Manager to version 6.0.0.3 or later.
3
What systems are affected by CVE-2014-6095?
CVE-2014-6095 affects IBM Security Identity Manager versions 6.0.0.0, 6.0.0.1, 6.0.0.2, and 6.0.0.3.
4
What types of attacks can be performed using CVE-2014-6095?
CVE-2014-6095 can be exploited by remote attackers to read arbitrary files on the server.
5
Is CVE-2014-6095 being actively exploited?
There is no public indication that CVE-2014-6095 is being actively exploited, but it is advisable to apply the fixes due to its high severity.