First published: Fri Feb 13 2015(Updated: )
Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access arbitrary files via a .. (dot dot) in a URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Optim Performance Manager | =4.1.1 | |
IBM InfoSphere Optim Performance Manager | =4.1.1.1 | |
IBM InfoSphere Optim Performance Manager | =5.1.0 | |
Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6154 is classified as a moderate severity vulnerability due to its directory traversal nature.
To fix CVE-2014-6154, upgrade to the latest version of IBM Optim Performance Manager that addresses this vulnerability.
CVE-2014-6154 affects IBM Optim Performance Manager for DB2 versions 4.1.0.1 through 4.1.1 and 5.1 through 5.3.1.
Currently, there are no official workarounds for CVE-2014-6154, and applying patches is recommended.
CVE-2014-6154 is a directory traversal vulnerability that allows remote attackers to access arbitrary files.